{"id":"CVE-2026-89672","title":"kernel: nfsd: gate nfs2 setacl by argp->mask (CVE-2026-89672)","summary":"A flaw was found in the Linux kernel's Network File System (NFS) server daemon (`nfsd`). When processing NFSACL version 2 SETACL requests, the system could unintentionally remove a directory's default Access Control List (ACL) or both acce…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-266","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 7","enterprise_linux 8","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-16","sourceUpdated":"2026-09-16T12:14:06+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89672.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89672.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89672"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532465"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89672"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89672"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89672.mbox"},{"url":"https://git.kernel.org/stable/c/8e4422b05f410f95c51b68a0db4bf1d87f6d22f5"},{"url":"https://git.kernel.org/stable/c/e41d173d9dc735cecb15ab7aa63ecab09338f81b"},{"url":"https://git.kernel.org/stable/c/f951b22dbeec46f2e0fba81cb80d1b0c686b61eb"},{"url":"https://git.kernel.org/stable/c/37eea38e7898538f0ec5f1eb8b18d8646e4be41c"},{"url":"https://git.kernel.org/stable/c/a3a7e20ed66d3f04d37883c398da8a113b430769"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00522,"epssPercentile":0.43308,"scores":{"vendor":7,"cna":9.1},"ingestedAt":"2026-09-14T15:23:07.450Z","slug":"CVE-2026-89672","body":"## Overview\n\nA flaw was found in the Linux kernel's Network File System (NFS) server daemon (`nfsd`). When processing NFSACL version 2 SETACL requests, the system could unintentionally remove a directory's default Access Control List (ACL) or both access and default ACLs. This occurs because the `set_posix_acl()` function is called unconditionally, even if the request mask indicates that no ACLs should be set, leading to an unintended removal operation. This could allow an attacker to modify file system permissions without authorization.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-16 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89672.json)\n\n**kernel: nfsd: gate nfs2 setacl by argp->mask** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-16.\n\nAffected:\n\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n\n## Remediation\n\nAffected","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":205456,"id":"CVE-2026-89672","ts":1789576719236,"field":"cvss","old":"9.1","new":"7"},{"seq":205455,"id":"CVE-2026-89672","ts":1789576719236,"field":"severity","old":"critical","new":"high"},{"seq":197762,"id":"CVE-2026-89672","ts":1789384318742,"field":"cvss","old":"6.8","new":"9.1"},{"seq":197761,"id":"CVE-2026-89672","ts":1789384318742,"field":"severity","old":"medium","new":"critical"},{"seq":183371,"id":"CVE-2026-89672","ts":1789356675085,"field":"cvss","old":"9.1","new":"6.8"},{"seq":183370,"id":"CVE-2026-89672","ts":1789356675085,"field":"severity","old":"critical","new":"medium"},{"seq":153538,"id":"CVE-2026-89672","ts":1789285351198,"field":"cvss","old":null,"new":"9.1"},{"seq":153537,"id":"CVE-2026-89672","ts":1789285351198,"field":"severity","old":"none","new":"critical"},{"seq":147157,"id":"CVE-2026-89672","ts":1789270197625,"field":"cvss","old":null,"new":"6.8"},{"seq":147156,"id":"CVE-2026-89672","ts":1789270197625,"field":"severity","old":"none","new":"medium"},{"seq":108916,"id":"CVE-2026-89672","ts":1789183729527,"field":"cvss","old":null,"new":"6.8"},{"seq":108915,"id":"CVE-2026-89672","ts":1789183729527,"field":"severity","old":"none","new":"medium"}]}