Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-89693

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
21/09/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create()<br /> <br /> nfsd4_create() stores the return value of nfsd4_acl_to_attr() in<br /> status, but the switch(create-&gt;cr_type) block unconditionally<br /> overwrites it in every branch. ACL translation errors are silently<br /> discarded, and the CREATE proceeds without the requested ACL.<br /> <br /> Add an early exit check after nfsd4_acl_to_attr(), matching the<br /> pattern already used in nfsd4_setattr().<br /> <br /> [ cel: prefer NFS4ERR_BADTYPE over NFS4ERR_ATTRNOTSUPP ]

Impacto