OpenZFS Authorization Bypass Allows Unprivileged User Actions
CVE-2026-79619

7.3HIGH

Key Information:

Vendor

Openzfs

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-79619?

A vulnerability in OpenZFS on Linux allows unprivileged users to exploit several ioctl authorization checks. These checks mistakenly interpret capabilities within user-created, unprivileged namespaces as equivalent to actual host privileges. Exploiting this flaw enables a local user to perform critical operations such as creating, importing, or destroying pools, accessing the pool event log, and executing fault injections without needing regular root access. Only minimal permissions to access /dev/zfs are required, alongside the ability to create unprivileged user namespaces, which opens the door for potential security breaches.

Affected Version(s)

OpenZFS Linux 0 < 2.2.11

OpenZFS Linux 2.3.0 < 2.3.9

OpenZFS Linux 2.4.0 < 2.4.4

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Erica Windisch
Rob Norris
.