SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-53396

HIGH · CVSS 7.1 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's NFS server, specifically in the handling of POSIX ACLs during file creation, where errors in ACL conversion are ignored, leading to potential violations of NFS standards and unintentional file creation without proper ACLs. Additionally, this flaw can result in memory leaks due to improperly handled ACL allocations when certain operations fail. Organizations using Linux systems with NFS should prioritize addressing this vulnerability to ensure compliance with NFS protocols and to mitigate potential security risks associated with improper ACL management.

CVE
CVE-2026-53396
Severity
HIGH
CVSS
7.1
EPSS
0.27%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix posix_acl leak and ignored error in nfsd4_create_file nfsd4_create_file() has two bugs in its ACL handling: The return value of nfsd4_acl_to_attr() is silently discarded. When the NFSv4-to-POSIX ACL conversion fails (e.g., -EINVAL for unsupported ACE types), the file is created without any ACL and the client receives NFS4_OK. This violates RFC 7530/8881 which require the server to reject unsupported attributes on CREATE. When start_creating() fails after ACL attributes have been populated in attrs (either via nfsd4_acl_to_attr or via ownership transfer from open->op_dpacl/op_pacl), the function jumps to out_write which skips nfsd_attrs_free(). The posix_acl allocations are leaked. A client can trigger this repeatedly with OPEN(CREATE), ACL attributes, and an invalid filename (e.g., longer than NAME_MAX). Fix both by capturing the nfsd4_acl_to_attr() return value and by changing the early error paths to jump to out instead of out_write. Initialize child to ERR_PTR(-EINVAL) so that end_creating() is safe to call even if start_creating() was never reached.

Related CVEs

Other vulnerabilities affecting the same vendor(s)