CVE-2026-89671 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 NFSv3 ACL Decoder nfsd3_proc_setacl mask/acl_access/acl_default null pointer dereference

SecurityVulns

A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3 and classified as very critical. This vulnerability affects the function nfsd3_proc_setacl of the component NFSv3 ACL Decoder. The manipulation of the argument mask/acl_access/acl_default results in null pointer dereference.

This vulnerability is identified as CVE-2026-89671. The attack can be executed remotely. There is not any exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More