No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 26 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openzfs
Openzfs openzfs |
|
| Vendors & Products |
Openzfs
Openzfs openzfs |
Wed, 26 Aug 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg create, import, destroy), pool event log access (zpool events) and fault injection (zinject). Exploiting the problem requires only that the local user is permitted to open /dev/zfs (governed by local device permissions) and that the kernel permits unprivileged user namespace creation. No prior access to the target pool or its underlying devices is needed. | |
| Title | OpenZFS: user-namespace capability check allows unprivileged local authorization bypass | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-08-26T15:47:19.764Z
Reserved: 2026-08-25T08:10:52.983Z
Link: CVE-2026-79619
Updated: 2026-08-26T15:47:16.882Z
Status : Received
Published: 2026-08-26T13:19:24.003
Modified: 2026-08-26T16:16:43.457
Link: CVE-2026-79619
No data.
OpenCVE Enrichment
Updated: 2026-08-26T16:30:09Z