In the Linux kernel, the following vulnerability has been resolved: NFSD: NFSv4 file creation neglects setting ACL An NFSv4 client that sets an ACL with a named principal during file creation retri…
高危 CVSS 8.0
摘要
In the Linux kernel, the following vulnerability has been resolved: NFSD: NFSv4 file creation neglects setting ACL An NFSv4 client that sets an ACL with a named principal during file creation retrieves the ACL afterwards, and finds that it is only a default ACL (based on the mode bits) and not the ACL that was requested during file creation. This violates RFC 8881 section 6.4.1.3: "the ACL attribute is set as given". The issue occurs in nfsd_create_setattr(), which calls nfsd_attrs_valid() t…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://git.kernel.org/stable/c/214b396480061cbc8b16f2c518b2add7fbfa5192
- https://git.kernel.org/stable/c/381261f24f4e4b41521c0e5ef5cc0b9a786a9862
- https://git.kernel.org/stable/c/60dbdef2ebc2317266a385e4debdb1bb0e57afe1
- https://git.kernel.org/stable/c/75f91534f9acdfef77f8fa094313b7806f801725
- https://git.kernel.org/stable/c/913f7cf77bf14c13cfea70e89bcb6d0b22239562
- https://git.kernel.org/stable/c/bf4e671c651534a307ab2fabba4926116beef8c3
- https://git.kernel.org/stable/c/c182e1e0b7640f6bcc0c5ca8d473f7c57199ea3d
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html
时间线
- nvd_ingest NVD