On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg create, import, destroy), pool event log access (zpool events) and fault injection (zinject). Exploiting the problem requires only that the local user is permitted to open /dev/zfs (governed by local device permissions) and that the kernel permits unprivileged user namespace creation. No prior access to the target pool or its underlying devices is needed.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79619.json",
"cwe_ids": [
"CWE-863"
],
"cna_assigner": "canonical"
}{
"source": [
"AFFECTED_FIELD",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0.7.0"
},
{
"fixed": "2.2.11"
},
{
"introduced": "2.3.0"
},
{
"fixed": "2.3.9"
},
{
"introduced": "2.4.0"
},
{
"fixed": "2.4.4"
}
]
}