Any local user can set the internal ZFS metadata flag "$hasrecvd" on datasets via ZFS_IOC_SET_PROP.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 19 Aug 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Freebsd
Freebsd freebsd |
|
| Vendors & Products |
Freebsd
Freebsd freebsd |
Wed, 19 Aug 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated the calling user such that an unprivileged user is able to set metadata on a dataset indicating that the dataset has received properties from a zfs-recv(8) stream. Any local user can set the internal ZFS metadata flag "$hasrecvd" on datasets via ZFS_IOC_SET_PROP. | |
| Title | Incorrect user validation in ZFS_IOC_SET_PROP ioctl | |
| Weaknesses | CWE-863 | |
| References |
|
Status: PUBLISHED
Assigner: freebsd
Published:
Updated: 2026-08-19T05:15:37.371Z
Reserved: 2026-05-29T20:24:28.617Z
Link: CVE-2026-49431
No data.
Status : Received
Published: 2026-08-19T06:17:43.027
Modified: 2026-08-19T06:17:43.027
Link: CVE-2026-49431
No data.
OpenCVE Enrichment
Updated: 2026-08-19T12:30:04Z