{"id":"AZL-100163","summary":"CVE-2026-89693 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: check nfsd4_acl_to_attr() return value in nfsd4_create()\n\nnfsd4_create() stores the return value of nfsd4_acl_to_attr() in\nstatus, but the switch(create-\u003ecr_type) block unconditionally\noverwrites it in every branch. ACL translation errors are silently\ndiscarded, and the CREATE proceeds without the requested ACL.\n\nAdd an early exit check after nfsd4_acl_to_attr(), matching the\npattern already used in nfsd4_setattr().\n\n[ cel: prefer NFS4ERR_BADTYPE over NFS4ERR_ATTRNOTSUPP ]","modified":"2026-09-14T05:26:59Z","published":"2026-09-11T20:19:56Z","upstream":["CVE-2026-89693"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89693"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-100163.json"}}],"schema_version":"1.9.0"}