PT-2026-71931 · Openzfs+1 · Openzfs+1
CVE-2026-49430
·
Published
2026-06-17
·
Updated
2026-09-01
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenZFS (affected versions not specified)
Description
An integer overflow exists in the
ZFS IOC RECV NEW ioctl within the heal receive path. The issue occurs when a 64-bit payload size is truncated to a 32-bit integer during allocation, while the original 64-bit size is subsequently used as the length for a byteswap operation. A local user possessing the "receive" delegated ZFS permission can trigger kernel memory corruption by sending a crafted receive stream in heal mode.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Integer Overflow
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freebsd
Openzfs