CVE-2026-79619
On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivale
CVSS
—
No CVSS
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 26, 2026 · Last modified: Aug 27, 2026 · CWE-863
Not enough EPSS history yet.
On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg create, import, destroy), pool event log access (zpool events) and fault injection (zinject). Exploiting the problem requires only that the local user is permitted to open /dev/zfs (governed by local device permissions) and that the kernel permits unprivileged user namespace creation. No prior access to the target pool or its underlying devices is needed.
- github.comhttps://github.com/advisories/GHSA-mhf5-q8gw-qg9v
- github.comhttps://github.com/openzfs/zfs/pull/18959
- github.comhttps://github.com/openzfs/zfs/releases/tag/zfs-2.2.11
- github.comhttps://github.com/openzfs/zfs/releases/tag/zfs-2.3.9
- github.comhttps://github.com/openzfs/zfs/releases/tag/zfs-2.4.4
- seclists.orghttps://seclists.org/fulldisclosure/2026/Aug/40