CVE-2026-89693: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create() nfsd4_create() stores the return value of nfsd4_acl_to_attr() in status, but the switch(create->cr_type) block unconditionally overwrites it in every branch. ACL translation errors are silently discarded, and the CREATE proceeds without the requested ACL. Add an early exit check after nfsd4_acl_to_attr(), matching the pattern already used in nfsd4_setattr(). [ cel: prefer NFS4ERR_BADTYPE over NFS4ERR_ATTRNOTSUPP ]

Affected products

  • Linux Linux: from 5.10.220, before 5.11 (fixed in 5.11); from 5.15.154, before 5.16 (fixed in 5.16); from 6.0, before 6.12.111 (fixed in 6.12.111); from 6.13, before 6.18.51 (fixed in 6.18.51); from 6.19, before 7.2.4 (fixed in 7.2.4)

Published 2026-09-11. Last modified 2026-09-21.