Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-53397

30
FAUCET Score

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix posix_acl leak on SETACL decode failure nfsaclsvc_decode_setaclargs() and nfs3svc_decode_setaclargs() each call nfs_stream_decode_acl() twice, first for NFS_ACL and then for NFS_DFACL. Each successful call transfers ownership of a freshly allocated posix_acl into argp->acl_access or argp->acl_default. If the first call succeeds but the second fails, the decoder returns false and argp->acl_access is left dangling. ACLPROC2_SETACL.pc_release was wired to nfssvc_release_attrstat and ACLPROC3_SETACL.pc_release was wired to nfs3svc_release_fhandle. Both only call fh_put() and have no knowledge of the ACL fields on argp. The posix_acl_release() pairs sat at the out: labels inside nfsacld_proc_setacl() and nfsd3_proc_setacl(), but svc_process() skips pc_func when pc_decode returns false, so that cleanup is unreachable on decode failure: svc_process_common() pc_decode() /* decode_setaclargs: false */ /* pc_func skipped */ pc_release() /* fh_put only -- ACLs leaked */ The orphaned posix_acl is leaked for the lifetime of the server. Fix by adding nfsaclsvc_release_setacl() and nfs3svc_release_setacl(), which release both argp->acl_access and argp->acl_default in addition to fh_put(), and wiring them as pc_release for their respective SETACL procedures. pc_release runs on every path svc_process() takes after decode, including decode failure, so the posix_acl_release() pairs are removed from the proc functions' out: labels to keep ownership in one place. This matches the existing release_getacl() pattern used by the sibling GETACL procedures.

First published: Jul 19, 2026Last modified: Jul 20, 2026

Impacted Technologies

VendorProductVersion(s)CPE
LinuxLinux
2.6.13CNA affecteddefault affected
LinuxLinux
>= a257cdd0e2179630d3201c32ba14d7fcb3c3a055, < 0853ac544c590880d797b04daa33fcb72b6be0e1, >= a257cdd0e2179630d3201c32ba14d7fcb3c3a055, < 136b416593f1349cf6f72c8e3d18f0f204ee8545, >= a257cdd0e2179630d3201c32ba14d7fcb3c3a055, < 1e96239fddcefacf6afe6c498357be68eacbcabc, >= a257cdd0e2179630d3201c32ba14d7fcb3c3a055, < 887f92ceccf3eacd5f2402db21254d66372fae00, >= a257cdd0e2179630d3201c32ba14d7fcb3c3a055, < a5b42c1e4ff2befaa6b96f7cbf32174751eba083, >= a257cdd0e2179630d3201c32ba14d7fcb3c3a055, < b2eb1ffd511d1b3c3e21122f97cbbccea411e277, >= a257cdd0e2179630d3201c32ba14d7fcb3c3a055, < b94c4be77682aab06d65ca7296149e3bcfb37353, >= a257cdd0e2179630d3201c32ba14d7fcb3c3a055, < bd69a825485168ef74e815ecb286754b570fdcc7CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.53%
Probability of exploitation in next 30 days
EPSS Percentile
41.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0053 is in the 19th percentile among its peer group of 51,551 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

microsoft2026-Jul/CVE-2026-53397Moderate

nfsd: fix posix_acl leak on SETACL decode failure

Jul 14, 2026

References

git.kernel.org / stable/c/0853ac544c590880d797b04daa33fcb72b6be0e1
git.kernel.org / stable/c/136b416593f1349cf6f72c8e3d18f0f204ee8545
git.kernel.org / stable/c/1e96239fddcefacf6afe6c498357be68eacbcabc
git.kernel.org / stable/c/887f92ceccf3eacd5f2402db21254d66372fae00
git.kernel.org / stable/c/a5b42c1e4ff2befaa6b96f7cbf32174751eba083
git.kernel.org / stable/c/b2eb1ffd511d1b3c3e21122f97cbbccea411e277
git.kernel.org / stable/c/b94c4be77682aab06d65ca7296149e3bcfb37353
git.kernel.org / stable/c/bd69a825485168ef74e815ecb286754b570fdcc7