CVE-2026-89693

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2026
Last modified:
21/09/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create()<br /> <br /> nfsd4_create() stores the return value of nfsd4_acl_to_attr() in<br /> status, but the switch(create-&gt;cr_type) block unconditionally<br /> overwrites it in every branch. ACL translation errors are silently<br /> discarded, and the CREATE proceeds without the requested ACL.<br /> <br /> Add an early exit check after nfsd4_acl_to_attr(), matching the<br /> pattern already used in nfsd4_setattr().<br /> <br /> [ cel: prefer NFS4ERR_BADTYPE over NFS4ERR_ATTRNOTSUPP ]

Impact