7.3

CVE-2026-79619

OpenZFS: user-namespace capability check allows unprivileged local authorization bypass

On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg create, import, destroy), pool event log access (zpool events) and fault injection (zinject). Exploiting the problem requires only that the local user is permitted to open /dev/zfs (governed by local device permissions) and that the kernel permits unprivileged user namespace creation. No prior access to the target pool or its underlying devices is needed.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerOpenZFS
≫
Produkt OpenZFS
Default Statusunaffected
Version 0.7.0
Version < 2.2.11
Status affected
Version 2.3.0
Version < 2.3.9
Status affected
Version 2.4.0
Version < 2.4.4
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.035
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Canonical 7.3 0 0
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://github.com/openzfs/zfs/pull/18959
https://github.com/advisories/GHSA-mhf5-q8gw-qg9v
https://github.com/openzfs/zfs/releases/tag/zfs-2.4.4
https://github.com/openzfs/zfs/releases/tag/zfs-2.3.9
https://github.com/openzfs/zfs/releases/tag/zfs-2.2.11
https://seclists.org/fulldisclosure/2026/Aug/40