PT-2026-82094 · Openzfs+2 · Openzfs+2

·

CVE-2026-79619

·

Published

2026-08-26

·

Updated

2026-08-31

CVSS v4.0

7.3

High

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenZFS (affected versions not specified)
Description On Linux, several ioctl authorization checks incorrectly treat capabilities held within a user-created, unprivileged namespace as equivalent to actual host privileges. This allows an unprivileged local user to execute operations that typically require root access, such as pool-administrative tasks (create, import, destroy), accessing the pool event log via zpool events, and performing fault injection through zinject. Exploitation is possible if the local user can open /dev/zfs and the kernel allows the creation of unprivileged user namespaces. No prior access to the target pool or its underlying devices is required.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79619
ECHO-A835-6F03-EF3A
GHSA-MHF5-Q8GW-QG9V
USN-8705-1
USN-8705-2

Affected Products

Linuxmint
Openzfs
Ubuntu