CVE-2026-79619: Openzfs

High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.

On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg create, import, destroy), pool event log access (zpool events) and fault injection (zinject). Exploiting the problem requires only that the local user is permitted to open /dev/zfs (governed by local device permissions) and that the kernel permits unprivileged user namespace creation. No prior access to the target pool or its underlying devices is needed.

Affected products

  • Openzfs Openzfs: from 0.7.0, before 2.2.11 (fixed in 2.2.11); from 2.3.0, before 2.3.9 (fixed in 2.3.9); from 2.4.0, before 2.4.4 (fixed in 2.4.4)

Published 2026-08-26. Last modified 2026-08-28.