Executive brief
A vulnerability in the Linux kernel's Network File System (NFS) server component can cause security settings to be ignored when new files are created. When a user creates a file and specifies specific access permissions (ACLs), the system may fail to apply them, instead reverting to basic default permissions. This could lead to unauthorized access if the intended restrictive permissions are not properly enforced on the storage server.
Technical details
A flaw exists in the NFSD component of the Linux kernel where NFSv4 file creation neglects to set requested Access Control Lists (ACLs). The root cause is in the nfsd_create_setattr() function, which relies on nfsd_attrs_valid() to decide whether to apply attributes. Because nfsd_attrs_valid() previously only checked for iattr changes and security labels, it would return false when only a POSIX ACL was present. Consequently, nfsd_setattr() was skipped, and the inode was created with default mode-based permissions instead of the client-specified ACL. This violates RFC 8881 requirements. Patches have been released for various stable kernel branches (e.g., 5.10.y, 6.1.y, 6.6.y, 6.12.y).
Affected products
- Linux Linux Kernel 5.10.220 to 5.10.248; 6.1.y; 6.6.y; 6.12.y
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6
- Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP V3.1.6
- Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP V3.1.6
Timeline
- 2025-11-18: disclosed: Initial patch submission by Chuck Lever
- 2026-01-02: patched: Patch committed to stable tree
- 2026-01-13: advisory: CVE published
References
- https://git.kernel.org/stable/c/214b396480061cbc8b16f2c518b2add7fbfa5192
- https://git.kernel.org/stable/c/381261f24f4e4b41521c0e5ef5cc0b9a786a9862
- https://git.kernel.org/stable/c/60dbdef2ebc2317266a385e4debdb1bb0e57afe1
- https://git.kernel.org/stable/c/75f91534f9acdfef77f8fa094313b7806f801725
- https://git.kernel.org/stable/c/913f7cf77bf14c13cfea70e89bcb6d0b22239562
- https://git.kernel.org/stable/c/bf4e671c651534a307ab2fabba4926116beef8c3
- https://git.kernel.org/stable/c/c182e1e0b7640f6bcc0c5ca8d473f7c57199ea3d