Answer in brief
CVE-2026-68149 records a High severity (CVSS 8.4) vulnerability in fs: preserve ACL_DONT_CACHE state in forget_cached_acl(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.4. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=facd61053cff100973921d4d45d47cf53c747ec6 <b98fad81f1202b0eb26aacf3ff4cc7a21ed3b5bf || >=facd61053cff100973921d4d45d47cf53c747ec6 <834ddf899484a2f23129080e8773bc04f4691d07 || >=facd61053cff100973921d4d45d47cf53c747ec6 <a019b074903b3ad0a9726087efd0e8291452023b || >=facd61053cff100973921d4d45d47cf53c747ec6 <ca03a7984a34f48085fd013e0d2cf4e6420b4acf || >=facd61053cff100973921d4d45d47cf53c747ec6 <4b9a5458d02e214ef2b384124ca626e3e381d778 | b98fad81f1202b0eb26aacf3ff4cc7a21ed3b5bf, 834ddf899484a2f23129080e8773bc04f4691d07, a019b074903b3ad0a9726087efd0e8291452023b, ca03a7984a34f48085fd013e0d2cf4e6420b4acf, 4b9a5458d02e214ef2b384124ca626e3e381d778 |
| Linux/Linuxgeneric | 6.2 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: fs: preserve ACL_DONT_CACHE state in forget_cached_acl() The ACL_DONT_CACHE state is meant to be a constant state for the inode for filesystems that want to opt out of posix acl caching. Commit facd61053cff1 ("fuse: fixes after adapting to new posix acl api") used this facility to opt out of posix acl caching for fuse inodes with fuse server that does not negotiate FUSE_POSIX_ACL (fc->posix_acl). The commit also takes care to gate the forget_all_cached_acls() call in fuse_set_acl() on fc->posix_acl because there is no need for it, but there are other placed in fuse code which call forget_all_cached_acls() unconditional to fc->posix_acl and those cause the loss of the ACL_DONT_CACHE state. This is not only a functional bug. Properly timed, a get_acl() from this fuse filesystem can return a stale cached value, as was observed in tests, because set_acl() does not invalidate the unintentional acl cache. We could fix this in fuse, but it actually makes no sense for the vfs helper forget_cached_acl() to invalidate the ACL_DONT_CACHE state, so let it not do that to fix fuse and future users of ACL_DONT_CACHE.
Quoted source text, attributed separately from HOL analysis.