CVE-2026-79619: OpenZFS: user-namespace capability check allows unprivileged local authorization bypass

Published Aug 26, 2026
·
Updated

On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg create, import, destroy), pool event log access (zpool events) and fault injection (zinject). Exploiting the problem requires only that the local user is permitted to open /dev/zfs (governed by local device permissions) and that the kernel permits unprivileged user namespace creation. No prior access to the target pool or its underlying devices is needed.

Affected Software

1 affected component
OpenZFS OpenZFS

Event History

Aug 26, 2026
CVE Published
via MITRE·12:50 PM
Data Sourced
via MITRE·12:50 PM
DescriptionWeakness

Frequently Asked Questions

1

Which systems are realistically exposed to this issue?

Linux systems are exposed when unprivileged users can open /dev/zfs and the kernel allows unprivileged user-namespace creation. The issue does not require the user to already have access to a target ZFS pool or its underlying devices.

2

What does an attacker need to exploit it?

An attacker needs local unprivileged access, permission to open /dev/zfs under the system's device-permission policy, and the ability to create an unprivileged user namespace. No host-root capability or prior pool access is required.

3

What can an attacker do after exploiting the authorization bypass?

The affected ioctl checks can authorize operations that should require root, including pool administration such as creating, importing, or destroying pools. They can also access pool event logs through zpool events and perform fault injection with zinject.

4

What can be done if updating OpenZFS is not immediately possible?

Restrict unprivileged users' access to /dev/zfs and disable or otherwise prevent unprivileged user-namespace creation where operationally feasible. Both conditions are required for exploitation based on the available information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203