{"id":"CVE-2026-79619","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-79619","summary":"On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged…","details":"On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg create, import, destroy), pool event log access (zpool events) and fault injection (zinject). Exploiting the problem requires only that the local user is permitted to open /dev/zfs (governed by local device permissions) and that the kernel permits unprivileged user namespace creation. No prior access to the target pool or its underlying devices is needed.","published":"2026-08-26T13:19:24.003","modified":"2026-08-26T16:16:43.457","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/openzfs/zfs/pull/18959","label":"openzfs/zfs#18959"},"references":[{"type":"WEB","url":"https://github.com/advisories/GHSA-mhf5-q8gw-qg9v"},{"type":"WEB","url":"https://github.com/openzfs/zfs/pull/18959"},{"type":"WEB","url":"https://github.com/openzfs/zfs/releases/tag/zfs-2.2.11"},{"type":"WEB","url":"https://github.com/openzfs/zfs/releases/tag/zfs-2.3.9"},{"type":"WEB","url":"https://github.com/openzfs/zfs/releases/tag/zfs-2.4.4"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-26T16:16:43.457"}}