Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 26 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openzfs
Openzfs openzfs |
|
| Vendors & Products |
Openzfs
Openzfs openzfs |
Wed, 26 Aug 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg create, import, destroy), pool event log access (zpool events) and fault injection (zinject). Exploiting the problem requires only that the local user is permitted to open /dev/zfs (governed by local device permissions) and that the kernel permits unprivileged user namespace creation. No prior access to the target pool or its underlying devices is needed. | |
| Title | OpenZFS: user-namespace capability check allows unprivileged local authorization bypass | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-08-26T15:47:19.764Z
Reserved: 2026-08-25T08:10:52.983Z
Link: CVE-2026-79619
Updated: 2026-08-26T15:47:16.882Z
Status : Received
Published: 2026-08-26T13:19:24.003
Modified: 2026-08-26T16:16:43.457
Link: CVE-2026-79619
No data.
OpenCVE Enrichment
Updated: 2026-08-26T16:30:09Z