Back

HIGH

nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create()

Published Sep 11, 2026

Description

nfsd4_create() stores the return value of nfsd4_acl_to_attr() in status, but the switch(create->cr_type) block unconditionally overwrites it in every branch. ACL translation errors are silently discarded, and the CREATE proceeds without the requested ACL.

Add an early exit check after nfsd4_acl_to_attr(), matching the pattern already used in nfsd4_setattr().

[ cel: prefer NFS4ERR_BADTYPE over NFS4ERR_ATTRNOTSUPP ]

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Sep 11, 2026
Updated Sep 21, 2026
Reserved Sep 11, 2026
NVD
Status Received
Modified Sep 11, 2026
Red Hat
Severity Moderate
Public date Sep 11, 2026
ENISA EUVD
Assigner Linux
Published Sep 11, 2026
Updated Sep 21, 2026
Exploited since n/a
EUVD-2026-76605