In the Linux kernel, the following vulnerability has been resolved:
nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create()
nfsd4_create() stores the return value of nfsd4_acl_to_attr() in
status, but the switch(create->cr_type) block unconditionally
overwrites it in every branch. ACL translation errors are silently
discarded, and the CREATE proceeds without the requested ACL.
Add an early exit check after nfsd4_acl_to_attr(), matching the
pattern already used in nfsd4_setattr().
[ cel: prefer NFS4ERR_BADTYPE over NFS4ERR_ATTRNOTSUPP ]
CVE-2026-89693
NONE
EPSS 0.17%
Updated Sep 21, 2026
Linux
https://git.kernel.org/stable/c/2c7912732184773dbd371a411da87af1cc080b86
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/430ed49a16cf9ca249d0fb51490582090bc4848b
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/80cebb0e8a8d1e758f0d671f5e047279c5c3e528
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/26877d3a09afb3838a053867a655ca30c46a1f81
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVE Details
CVE ID
CVE-2026-89693
Published Date
Sep 11, 2026
Vendor
Linux
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.17%
Likelihood of exploitation in next 30 days
Percentile:
5.5th percentile (higher than 5.5% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory