๐Ÿ” CVE Alert

CVE-2026-79619

UNKNOWN 0.0

OpenZFS: user-namespace capability check allows unprivileged local authorization bypass

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg create, import, destroy), pool event log access (zpool events) and fault injection (zinject). Exploiting the problem requires only that the local user is permitted to open /dev/zfs (governed by local device permissions) and that the kernel permits unprivileged user namespace creation. No prior access to the target pool or its underlying devices is needed.

CWE CWE-863
Vendor openzfs
Product openzfs
Published Aug 26, 2026
Last Updated Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for openzfs openzfs

Be the first to know when new unknown vulnerabilities affecting openzfs openzfs are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

OpenZFS / OpenZFS
0 < 2.2.11 2.3.0 < 2.3.9 2.4.0 < 2.4.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openzfs/zfs/pull/18959 github.com: https://github.com/advisories/GHSA-mhf5-q8gw-qg9v github.com: https://github.com/openzfs/zfs/releases/tag/zfs-2.4.4 github.com: https://github.com/openzfs/zfs/releases/tag/zfs-2.3.9 github.com: https://github.com/openzfs/zfs/releases/tag/zfs-2.2.11

Credits

๐Ÿ” Erica Windisch Rob Norris