CVE-2026-79619
OpenZFS: user-namespace capability check allows unprivileged local authorization bypass
On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg create, import, destroy), pool event log access (zpool events) and fault injection (zinject). Exploiting the problem requires only that the local user is permitted to open /dev/zfs (governed by local device permissions) and that the kernel permits unprivileged user namespace creation. No prior access to the target pool or its underlying devices is needed.
| CWE | CWE-863 |
| Vendor | openzfs |
| Product | openzfs |
| Published | Aug 26, 2026 |
| Last Updated | Aug 26, 2026 |
Get instant alerts for openzfs openzfs
Be the first to know when new unknown vulnerabilities affecting openzfs openzfs are published โ delivered to Slack, Telegram or Discord.