Executive brief
A vulnerability in the Linux kernel's Network File System (NFS) server component could allow files to be created with incorrect security permissions. Additionally, a remote user could repeatedly trigger a memory leak by attempting to create files with invalid names, potentially leading to system instability or a denial-of-service over time. This affects systems acting as NFS servers in enterprise environments.
Technical details
Two distinct issues exist within the nfsd4_create_file() function in the Linux kernel's NFS server. First, the return value of nfsd4_acl_to_attr() is ignored, causing the server to create files without Access Control Lists (ACLs) and return success even when ACL conversion fails, violating RFC 7530/8881. Second, a memory leak occurs when start_creating() fails (e.g., due to a filename exceeding NAME_MAX) because the code jumps to a label that bypasses nfsd_attrs_free(), leaving posix_acl allocations in memory. An attacker can exploit the leak remotely by repeatedly sending OPEN(CREATE) requests with ACL attributes and invalid filenames. The issues have been resolved by properly checking return values and correcting the error-handling jump paths.
Affected products
- Linux Linux 6.19, 7.1.3, 7.2-rc1
Timeline
- 2026-05-21: other: Patch authored
- 2026-07-19: disclosed: CVE published