Executive brief
The Linux kernel's NFS server implementation has a logic error in its NFSACLv2 SETACL handler that unintentionally deletes file Access Control Lists (ACLs) when they are not explicitly modified in a client request. An attacker with NFS access can issue crafted SETACL requests to silently remove default ACLs from directories, potentially bypassing intended file permission protections and gaining unauthorized access to files.
Technical details
The vulnerability is a logic error in the nfsacld_proc_setacl() function within fs/nfsd/nfs2acl.c. The NFSACL v2 decoder leaves ACL pointers NULL when the corresponding mask bits (NFS_ACL or NFS_DFACL) are not set in the request, but the handler unconditionally passes both pointers to set_posix_acl(). Calling set_posix_acl() with a NULL ACL pointer triggers the "remove ACL" operation in the VFS layer, making an omitted ACL indistinguishable from an explicit deletion request. An attacker can send a SETACL request with only NFS_ACL set to silently strip a directory's default ACL, or send mask=0 to strip both access and default ACLs. The fix adds conditional checks on the mask bits before calling set_posix_acl(), ensuring unspecified ACLs are left untouched.
Affected products
- Linux Linux Kernel 2.6.11 through 7.2 and later (versions affected vary by stable branch)
Timeline
- 2026-09-11: disclosed: Published to NVD
- 2026-05-30: patched: Fix committed upstream by Chuck Lever (commit a3a7e20ed66d3f04d37883c398da8a113b430769)
- 2026-09-07: patched: Patch backported to stable branch (commit 37eea38e7898538f0ec5f1eb8b18d8646e4be41c)
- 2026-09-14: patched: Patch backported to additional stable branches