Database/Control plane, storage & DevOps
Linux NFS server (nfsd, NFSv4 file creation ACL): When a client sets an ACL during NFSv4 file creation, nfsd silently
Impact
When a client sets an ACL during NFSv4 file creation, nfsd silently drops it and falls back to an ACL derived from the mode bits. Files a tenant believed were restricted to a named principal are actually governed by looser mode-derived permissions, so other users on the shared export can read them.
Who can reach it
Any NFSv4 client creating files with an ACL naming a principal. The exposure is created by the server, not by an attacker action - the attacker just has to be another user on the export.
What to do
Update the storage server kernel to one carrying the nfsd_create_setattr ACL fix and reboot. Then re-apply ACLs on files created during the exposure window, since the intended ACLs were never written to the inodes.
References
Related entries
- Lantronix Provisioning Manager: Provisioning Manager reads configuration files supplied by the network devicesCVE-2025-7766 · Lantronix Provisioning ManagerHigh
- Progress Kemp LoadMaster Multi Tenant: The Multi Tenant product line's REST API doesn't check whether a caller'sCVE-2026-59690 · Progress Kemp LoadMaster Multi TenantHigh
- Jenkins SonarQube Scanner Plugin: unrestricted URL scheme in dashboard links causes stored XSSCVE-2026-84665 · Jenkins SonarQube Scanner Plugin (dashboard link generation)High
- Jenkins Script Security Plugin (classpath entry approval): Script Security normally requires an administrator toCVE-2026-92127 · Jenkins Script Security Plugin (classpath entry approval)High
- Jenkins Warnings Plugin: unvalidated analysis results ID allows stored XSS in the controller UICVE-2026-92134 · Jenkins Warnings Plugin (analysis results ID validation)High
- Jenkins Coverage Plugin: unvalidated coverage results ID allows stored XSS in the controller UICVE-2026-92135 · Jenkins Coverage Plugin (coverage results ID validation)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.