CVE-2026-89693
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2026
Last modified:
21/09/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create()<br />
<br />
nfsd4_create() stores the return value of nfsd4_acl_to_attr() in<br />
status, but the switch(create->cr_type) block unconditionally<br />
overwrites it in every branch. ACL translation errors are silently<br />
discarded, and the CREATE proceeds without the requested ACL.<br />
<br />
Add an early exit check after nfsd4_acl_to_attr(), matching the<br />
pattern already used in nfsd4_setattr().<br />
<br />
[ cel: prefer NFS4ERR_BADTYPE over NFS4ERR_ATTRNOTSUPP ]


