Skip to main content

Threats Tagged 'cve-2025-68803'

View all threats tagged with 'cve-2025-68803'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2025-68803

Threats Tagged 'cve-2025-68803'

Click on any threat for detailed analysis and mitigation recommendations

A vulnerability in the Linux kernel's NFS server (NFSD) causes NFSv4 file creation to neglect setting the requested POSIX ACL. When an NFSv4 client sets an ACL with a named principal during file creation, the ACL returned afterwards is a default one derived from mode bits rather than the originally specified ACL. This behavior violates RFC 8881 section 6.4.1.3, which requires the ACL attribute to be set as given. The issue stems from the nfsd_create_setattr() function skipping the application of POSIX ACLs due to incomplete checks in nfsd_attrs_valid().

Join the discussion

In the Linux kernel, the following vulnerability has been resolved: NFSD: NFSv4 file creation neglects setting ACL An NFSv4 client that sets an ACL with a named principal during file creation retrieves the ACL afterwards, and finds that it is only a default ACL (based on the mode bits) and not the ACL that was requested during file creation. This violates RFC 8881 section 6.4.1.3: "the ACL attribute is set as given". The issue occurs in nfsd_create_setattr(), which calls nfsd_attrs_valid() to determine whether to call nfsd_setattr(). However, nfsd_attrs_valid() checks only for iattr changes and security labels, but not POSIX ACLs. When only an ACL is present, the function returns false, nfsd_setattr() is skipped, and the POSIX ACL is never applied to the inode. Subsequently, when the client retrieves the ACL, the server finds no POSIX ACL on the inode and returns one generated from the file's mode bits rather than returning the originally-specified ACL.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: cve-2025-68803
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses