PT-2026-71931 · Openzfs+1 · Openzfs+1

CVE-2026-49430

·

Published

2026-06-17

·

Updated

2026-09-01

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenZFS (affected versions not specified)
Description An integer overflow exists in the ZFS IOC RECV NEW ioctl within the heal receive path. The issue occurs when a 64-bit payload size is truncated to a 32-bit integer during allocation, while the original 64-bit size is subsequently used as the length for a byteswap operation. A local user possessing the "receive" delegated ZFS permission can trigger kernel memory corruption by sending a crafted receive stream in heal mode.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Integer Overflow

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11473
CVE-2026-49430

Affected Products

Freebsd
Openzfs