CVE-2026-79619

NameCVE-2026-79619
DescriptionOn Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg create, import, destroy), pool event log access (zpool events) and fault injection (zinject). Exploiting the problem requires only that the local user is permitted to open /dev/zfs (governed by local device permissions) and that the kernel permits unprivileged user namespace creation. No prior access to the target pool or its underlying devices is needed.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6462-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
zfs-linux (PTS)bookworm/contrib2.1.11-1+deb12u1vulnerable
trixie/contrib, trixie/contrib (security)2.3.9-0+deb13u1fixed
forky/contrib, sid/contrib2.4.4-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
zfs-linuxsourcetrixie2.3.9-0+deb13u1DSA-6462-1
zfs-linuxsource(unstable)2.4.4-1

Notes

https://github.com/openzfs/zfs/security/advisories/GHSA-mhf5-q8gw-qg9v
https://www.openwall.com/lists/oss-security/2026/08/16/5
https://github.com/openzfs/zfs/issues/18936
https://github.com/openzfs/zfs/pull/18959

Search for package or bug name: Reporting problems