External risk intelligence

Linux Kernel NFSv2 ACL Vulnerability Allows Unintended Deletion

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-89672

The vulnerability exists in the Linux kernel NFS (Network File System) implementation, specifically regarding ACL handling. While NFS can be exposed to a network, it is typically deployed within trusted, internal enterprise or data center network segments rather than being directly exposed to the public internet.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been resolved in the Linux kernel affecting the Network File System (NFS) service. This issue could allow an attacker to unintentionally remove or modify access control lists (ACLs) on shared files or directories. While the potential for unauthorized modification or deletion of data exists, the specific impact depends on how NFS and ACLs are configured within your environment.

  • Issue: Unintended deletion/modification of file access controls.
  • Why remember: Impacts file access integrity on shared systems.
  • Executive takeaway: Confirm relevance and scope of NFS usage.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted NFSv2 SETACL request to a vulnerable Linux kernel system. This request, when processed by the nfsd component, could be misinterpreted by the `set_posix_acl` function, leading to unintended modifications or deletions of Access Control Lists (ACLs). The vulnerability allows an attacker to bypass intended access controls or remove existing ones, potentially impacting the confidentiality and integrity of the file system.

  • Network access to NFS service required.
  • Malicious SETACL request triggers vulnerability.
  • Allows unauthorized ACL modification or deletion.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, this vulnerability could allow an unauthenticated attacker to affect the behavior of the NFSv2 service, potentially leading to the unintended removal of default Access Control Lists (ACLs) on directories.

  • Directory ACLs
  • Unauthenticated network access
  • ACLs may be deleted unintentionally

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the Linux kernel's NFSd component, specifically affecting NFSv2 SETACL operations, likely falls under the purview of infrastructure or platform teams responsible for managing the NFS service. The first practical step involves identifying all NFSv2 servers, determining their network accessibility and criticality, and then locating the accountable owner for remediation.

  • Identify NFSv2 servers and assess exposure.
  • Confirm ownership and business criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Linux kernel's nfsd component?

The nfsd component is the server-side implementation of the Network File System (NFS) within the Linux kernel. It allows a Linux system to share directories and files over a network, enabling remote computers to access this storage as if it were local. NFS is widely used in data centers and enterprise environments to provide centralized file sharing, making it a critical service for managing collaborative storage, home directories, and application data across many connected machines.

What is the weakness class in CVE-2026-89672?

This vulnerability is an improper input validation issue. Specifically, the system fails to correctly distinguish between a request to modify an Access Control List (ACL) and a request to delete one when certain parameters are missing. Because the software assumes an omitted instruction is a command to remove existing security permissions, it accidentally applies these deletions when processing NFSv2 SETACL requests, potentially leaving sensitive files unprotected.

How does an attacker trigger this NFSv2 flaw?

An attacker triggers this by sending a specially crafted NFSv2 SETACL network request that omits specific mask bits. Importantly, the vulnerability is not triggered by standard, valid file access operations or administrative tasks that properly include the necessary request flags. It only occurs when the nfsd component receives an incomplete set of instructions, causing the system to mistakenly interpret the missing data as a command to strip away directory security settings.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal assesses the risk as unlikely for most systems. While the NFS service can be reached over a network, it is traditionally deployed within protected, internal enterprise network segments or private data centers rather than being directly exposed to the public internet. If your NFS infrastructure is restricted to trusted internal networks, the likelihood of an external, unauthenticated attacker successfully reaching and exploiting this service is significantly reduced.

What should I do if I run Linux NFS servers?

Your first step is to inventory your environment to identify all servers actively running NFSv2. Once identified, evaluate the network accessibility of these systems to determine if they are reachable from untrusted zones. Coordinate with your infrastructure team to verify ownership and business criticality for these assets, then prepare to apply the necessary kernel updates or patches once they are released by your distribution vendor to remediate the ACL handling defect.

References