CVE-2026-79619

EUVD-2026-66419
On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg create, import, destroy), pool event log access (zpool events) and fault injection (zinject). Exploiting the problem requires only that the local user is permitted to open /dev/zfs (governed by local device permissions) and that the kernel permits unprivileged user namespace creation. No prior access to the target pool or its underlying devices is needed.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
canonicalCNA
7.3 HIGH
LOCAL
LOW
LOW
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 3.54%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
openzfsopenzfs
0.7.0 ≤
𝑥
< 2.2.11
CNA
openzfsopenzfs
2.3.0 ≤
𝑥
< 2.3.9
CNA
openzfsopenzfs
2.4.0 ≤
𝑥
< 2.4.4
CNA
Debian logo
Debian Releases
Debian Product
Codename
zfs-linux
bookworm/contrib
vulnerable
bullseye/contrib
vulnerable
bullseye/contrib (security)
vulnerable
forky/contrib
2.4.4-1
fixed
sid/contrib
2.4.4-1
fixed
trixie/contrib
vulnerable
trixie/contrib (security)
2.3.9-0+deb13u1
fixed