CVE-2026-89671
A flaw in the Linux kernel’s NFSv3 setacl handling could let an attacker delete or alter file access controls. The bug misinterprets missing ACL data as a removal, causing ACLs to be unintentionally dropped. The issue has been fixed in the kernel.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, any version before the fix, especially systems running NFSv3 servers. System administrators and users of NFS file shares are the typical users.
Real-world impact
An attacker could remove or modify ACLs on files exposed via NFS, potentially granting unauthorized access or denying legitimate users. This could lead to data exposure or loss of integrity.
Why this severity
The CVSS score of 9.1 reflects that the vulnerability is network‑exploitable, requires no privileges, and can compromise confidentiality and integrity by allowing an attacker to change ACLs on NFS‑exported files.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the fix for CVE-2026-89671.
NVD-referenced vendor advisory
Timeline
- Sep 11, 2026 · 2d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 13, 2026 · 7h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.