CVE-2026-79619
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg create, import, destroy), pool event log access (zpool events) and fault injection (zinject). Exploiting the problem requires only that the local user is permitted to open /dev/zfs (governed by local device permissions) and that the kernel permits unprivileged user namespace creation. No prior access to the target pool or its underlying devices is needed.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OpenZFS | OpenZFS | 0 < 2.2.11 | affected |
| OpenZFS | OpenZFS | 2.3.0 < 2.3.9 | affected |
| OpenZFS | OpenZFS | 2.4.0 < 2.4.4 | affected |
Weaknesses
- CWE-863: CWE-863 Incorrect Authorization
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://github.com/openzfs/zfs/pull/18959
- https://github.com/advisories/GHSA-mhf5-q8gw-qg9v
- https://github.com/openzfs/zfs/releases/tag/zfs-2.4.4
- https://github.com/openzfs/zfs/releases/tag/zfs-2.3.9
- https://github.com/openzfs/zfs/releases/tag/zfs-2.2.11
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.