ZFS Metadata Improper User Validation in FreeBSD
CVE-2026-49431

Currently unrated

Key Information:

Vendor

FreeBSD

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-49431?

The ZFS_IOC_SET_PROP ioctl in FreeBSD's ZFS is vulnerable due to inadequate validation of the calling user. As a result, unprivileged users can manipulate dataset metadata, allowing them to set the internal ZFS flag '$hasrecvd'. This vulnerability poses a risk as it can mislead the handling of dataset properties, impacting data management and security.

Affected Version(s)

FreeBSD 15.1-RELEASE

FreeBSD 15.0-RELEASE

FreeBSD 14.4-RELEASE

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yuxiang Yang, Yizhou Zhao, Ao Wang, Xuewei Feng, Qi Li, and Ke Xu from Tsinghua University using GLM-5.1 from Z.ai
Emmanuel Genier at Quarkslab
.