External risk intelligence

Linux Kernel NFSv3 ACL Handling Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-89671

This vulnerability exists in the Linux kernel's NFSv3 server implementation (nfsd). While NFS services are occasionally exposed directly to the internet in specific high-performance or specialized environments, they are overwhelmingly deployed within trusted internal networks, private data centers, or behind VPNs, making public internet exposure uncommon for this protocol.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This Linux kernel vulnerability relates to how the NFSv3 server handles access control lists when clients request changes. If not properly managed, this could allow unintended modifications or deletions of access permissions. The main concern is confirming whether this specific functionality is in use and exposed.

  • An issue with file access permissions in the Linux kernel.
  • Matters if your environment uses NFSv3 file sharing.
  • Confirm if NFSv3 access control is a factor.

Attack Path

How an attacker could exploit the issue

An attacker could leverage the NFSv3 protocol to manipulate Access Control Lists (ACLs) on a Linux kernel system. By sending a specially crafted request, an attacker could trick the NFS server into removing existing ACLs, potentially leading to unauthorized access or modification of files and directories. This vulnerability allows for a critical loss of confidentiality and integrity.

  • Network access required, no special privileges.
  • Triggered by NFSv3 SETACL requests.
  • Risk of unauthorized access and data modification.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated remote attacker to manipulate Access Control Lists (ACLs) on an NFSv3 server. When an NFSv3 client requests to modify an ACL, the server incorrectly handles requests where certain ACL types are not specified, potentially leading to the unintended removal or modification of existing ACLs. This could impact the integrity of file access permissions when supported by the advisory.

  • Server ACL integrity may be affected.
  • Malformed ACL requests could be processed.
  • Unauthorized access to file system data.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the Linux kernel's NFSv3 server implementation requires immediate attention from teams managing NFS services. The first practical step is to identify all NFS servers, confirm their exposure and criticality, and then determine the accountable owner for remediation.

  • Identify NFS server owners and exposure.
  • Verify server reachability and business impact.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Linux kernel nfsd component?

The nfsd, or NFS daemon, is a core Linux kernel component that enables Network File System (NFS) services. It allows a computer to act as a file server, letting remote clients access and manage files over a network. This specific issue relates to how the kernel handles NFSv3, an older but widely used version of the protocol, specifically when managing POSIX Access Control Lists that define which users or groups can read, write, or modify specific files and directories.

What does this CVE-2026-89671 weakness mean?

This vulnerability is an improper input validation issue. In the NFSv3 protocol, a client can send a command to set file access permissions. The server incorrectly fails to check if the client actually intended to modify a specific type of permission before applying changes. Because of this, the server treats a missing or empty request as a command to delete existing permissions, potentially stripping away security controls on files or directories without the administrator's knowledge.

How is this CVE-2026-89671 triggered?

An attacker triggers this by sending a specially crafted NFSv3 SETACL network request to the server. The flaw occurs because the server does not verify if the client request contains a valid instruction for specific ACL types. Crucially, a request that does not specify any ACL changes does not trigger the bug; it only occurs when an incomplete or malformed request is processed, causing the kernel to incorrectly clear the existing access list for that file system object.

Is my server at risk according to Halo Surface Signal?

Halo Surface Signal notes that this vulnerability affects the Linux kernel's NFSv3 server. While the bug is technically reachable via the network, Halo classifies public internet exposure as uncommon. NFS services are typically deployed within trusted internal networks, private data centers, or behind VPNs. You should prioritize internal systems that allow NFS traffic, as those are the most likely environments where this service would be active and accessible to potential attackers.

How should I respond to this NFS vulnerability?

Start by identifying all servers in your infrastructure running the Linux NFSv3 service. Once you have a list of active NFS servers, verify their network reachability and determine which systems handle sensitive data. Since this is a kernel-level issue, coordinate with your system administrators to plan for kernel updates as they become available. Focus on systems that are not protected by restrictive firewalls or VPNs first, as these present the highest immediate risk.

References