PT-2026-82094 · Openzfs+2 · Openzfs+2
CVSS v4.0
7.3
High
| Vector | AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenZFS (affected versions not specified)
Description
On Linux, several ioctl authorization checks incorrectly treat capabilities held within a user-created, unprivileged namespace as equivalent to actual host privileges. This allows an unprivileged local user to execute operations that typically require root access, such as pool-administrative tasks (create, import, destroy), accessing the pool event log via
zpool events, and performing fault injection through zinject. Exploitation is possible if the local user can open /dev/zfs and the kernel allows the creation of unprivileged user namespaces. No prior access to the target pool or its underlying devices is required.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Openzfs
Ubuntu