From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1654C58F099 for ; Fri, 11 Sep 2026 20:03:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789157023; cv=none; b=ZpNlE+F+pz1ZItsT9whoX7YVT7HilmJ70uszJ8dVZ5A6DEKAA2d5gMfn+y8wZ2C5BUBlPyo0RQG7Zw7G4BwRf3ae+S/XvDoG5rIOUPU9flaG3kenC+IUXUJiPrzO4Gu0KSJzORjeOi7ef7KXOKmXbcwxXcjdrxrS9bLIhAi6NUg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789157023; c=relaxed/simple; bh=KGpsd4zaxhN/GHAKyHohEwCXrCrXlVYwWdLrkhM2Euw=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=DkWTerO3y2DJJiE+JOwUyYyZ/q0aYkosguLA9ER+fN7GTkmnYIXBGZJ2D1JlhtrAoRuejCVs8zngCSuMiMkOdfSuLxShSasO7AGFkFUxMO44Hxk+MOCy9SAUzrbi8OTzTPgx5XPhpZpwTT3lH4Puf/EsgHCuaytbQDV5aa/7YyM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=MP4aapM6; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="MP4aapM6" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 6CA141F00893; Fri, 11 Sep 2026 20:03:26 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789157007; bh=6+AJGx4ejAnStziwmOqB8qpLpMH9PzWnZCZB/97rkQs=; h=From:To:Cc:Subject:Date:Reply-To; b=MP4aapM615FeTnuQQc1MOJxyt+ZaYDAIq/KgnnmgDhhGh5Mslee4rb2SOEdaptXXS Q8cb/3IiZPMkICfPw44kiJrcozPkO2UQueD46gxTdeFUnXWmzdLGHYo+/Zx22Exj01 PR8BNrA1eua519MvDO+wLEy2/to52h1kqkp6Tufc= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89671: nfsd: gate nfs3 setacl by argp->mask Date: Fri, 11 Sep 2026 21:46:00 +0200 Message-ID: <2026091148-CVE-2026-89671-bb67@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3602; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=HjxRph1Yg1vjntY3XnIb/rxUVuCB7d/Ztm7jxJuTYn4=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLImt3K7+wX1qi6DXvxs4NcsuEV8dvL7Xfy1nBc3qq8 bXH4isWd8SyMAgyMciKKbJ82cZzdH/FIUUvQ9vTMHNYmUCGMHBxCsBEOCsYFlyY8GrStBVPnc3U 3/Or/Dn8+1Z6yyGG+bW7d34wfjkl8n+wp+T72wI++os5swA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: nfsd: gate nfs3 setacl by argp->mask nfsd3_proc_setacl() calls set_posix_acl() unconditionally for both ACL_TYPE_ACCESS and ACL_TYPE_DEFAULT, passing argp->acl_access and argp->acl_default verbatim. The NFSv3 ACL decoder only populates those pointers when the corresponding mask bit is set: nfs3svc_decode_setaclargs() if (args->mask & NFS_ACL) decode into acl_access if (args->mask & NFS_DFACL) decode into acl_default /* otherwise the pointer stays NULL (pc_argzero) */ nfsd3_proc_setacl() set_posix_acl(.., ACL_TYPE_ACCESS, argp->acl_access) set_posix_acl(.., ACL_TYPE_DEFAULT, argp->acl_default) set_posix_acl(idmap, dentry, type, NULL) is the VFS "remove this ACL type" operation. A NULL pointer that means "the client did not send this arm" is therefore indistinguishable from "the client asked to remove this ACL". A SETACL with mask=NFS_ACL silently drops the directory's default ACL; mask=0 drops both. The sibling nfsd3_proc_getacl() already consults argp->mask before touching each arm; mirror that in setacl. Fix by wrapping each set_posix_acl() call in the matching mask bit check and initializing error to 0 before inode_lock so that a request with neither bit set leaves the on-disk ACLs untouched and returns nfs_ok. The out_drop_lock path and the unconditional posix_acl_release() at out: are preserved; both NULL-tolerate the skipped arms. The Linux kernel CVE team has assigned CVE-2026-89671 to this issue. Affected and fixed versions =========================== Issue introduced in 2.6.13 with commit a257cdd0e2179630d3201c32ba14d7fcb3c3a055 and fixed in 6.12.109 with commit 68a80b26efdff1d09f8ae1773c6a915abb9e191d Issue introduced in 2.6.13 with commit a257cdd0e2179630d3201c32ba14d7fcb3c3a055 and fixed in 6.18.50 with commit b3bff820d068ea59767d4e91a3258231a879da5f Issue introduced in 2.6.13 with commit a257cdd0e2179630d3201c32ba14d7fcb3c3a055 and fixed in 7.2.4 with commit ff99ed007f065198fd723152405c22aa558f700b Issue introduced in 2.6.13 with commit a257cdd0e2179630d3201c32ba14d7fcb3c3a055 and fixed in 7.3-rc1 with commit 453d7198a0ab07a12d46e0575861ac7b932da17e Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89671 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/nfsd/nfs3acl.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/68a80b26efdff1d09f8ae1773c6a915abb9e191d https://git.kernel.org/stable/c/b3bff820d068ea59767d4e91a3258231a879da5f https://git.kernel.org/stable/c/ff99ed007f065198fd723152405c22aa558f700b https://git.kernel.org/stable/c/453d7198a0ab07a12d46e0575861ac7b932da17e