CVE-2026-49431: Incorrect user validation in ZFS_IOC_SET_PROP ioctl

Published Aug 19, 2026
·
Updated

The ZFSIOCSETPROP ioctl, used by zfs-set(8), incorrectly validated the calling user such that an unprivileged user is able to set metadata on a dataset indicating that the dataset has received properties from a zfs-recv(8) stream.

Any local user can set the internal ZFS metadata flag "$hasrecvd" on datasets via ZFSIOCSETPROP.

Affected Software

1 affected component
OpenZFS ZFS

Event History

Aug 19, 2026
CVE Published
via MITRE·05:15 AM
Data Sourced
via MITRE·05:15 AM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any local unprivileged user can exploit it. The issue requires local access to invoke the ZFS_IOC_SET_PROP ioctl; no remote attack path is described.

2

What changes can an attacker make?

An attacker can set the internal "$hasrecvd" metadata flag on datasets, causing metadata to indicate that the dataset received properties from a zfs-recv(8) stream.

3

How can I determine whether a system may have been affected?

Review dataset metadata for the internal "$hasrecvd" flag, particularly on datasets where no corresponding zfs-recv(8) stream was expected. The provided information does not specify a detection command or remediation procedure.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203