Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-79619— OpenZFS: user-namespace capability check allows unprivileged local authorization bypass

Quick assessment

Affected
OpenZFS OpenZFS
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 系统中,OpenZFS 的多个 ioctl 授权检查存在一个安全缺陷:这些检查将仅在用户创建的、无特权的命名空间(user namespace)内持有的权限(capability)等同于真实的宿主机特权,从而允许一个普通的本地用户执行本应需要 root 权限才能完成的操作。 受此问题影响的操作包括: 池管理操作(如创建、导入、销毁存储池) 池事件日志访问(zpool events) 故障注入(zinject) 要利用该漏洞,本地用户只需满足两个条件: 1. 被允许访问 设备(受本地设备权限控制);

CVSS 7.3 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-79619

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OpenZFS: user-namespace capability check allows unprivileged local authorization bypass
Source: CVE Program / CVE List V5
Vulnerability Description
On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg create, import, destroy), pool event log access (zpool events) and fault injection (zinject). Exploiting the problem requires only that the local user is permitted to open /dev/zfs (governed by local device permissions) and that the kernel permits unprivileged user namespace creation. No prior access to the target pool or its underlying devices is needed.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
OpenZFS OpenZFS 0 ~ 2.2.11 -

II. Public POCs for CVE-2026-79619

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 8864 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-79619

登录查看更多情报信息。

Patches & Fixes for CVE-2026-79619 (1)

Vendor Advisories for CVE-2026-79619 (1)

Vendor Pages for CVE-2026-79619 (2)

Other References for CVE-2026-79619 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-79619

No comments yet


Leave a comment