CVE-2026-79619

Publication date 27 August 2026

Last updated 1 September 2026


Ubuntu priority

Description

On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg create, import, destroy), pool event log access (zpool events) and fault injection (zinject). Exploiting the problem requires only that the local user is permitted to open /dev/zfs (governed by local device permissions) and that the kernel permits unprivileged user namespace creation. No prior access to the target pool or its underlying devices is needed.

Why is this CVE high priority?

See ubuntu cvss score

Learn more about Ubuntu priority

Status

Package Ubuntu Release Status
zfs-linux 26.04 LTS resolute
Fixed 2.4.1-1ubuntu5.1
24.04 LTS noble
Fixed 2.2.2-0ubuntu9.5
22.04 LTS jammy
Fixed 2.1.5-1ubuntu6~22.04.7
20.04 LTS focal
Fixed 0.8.3-1ubuntu12.18+esm1
18.04 LTS bionic
Fixed 0.7.5-1ubuntu16.12+esm1
16.04 LTS xenial
Not affected

Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

Get Ubuntu Pro 30-day free trial

Severity score breakdown

CVSS version: CVSS v4.0

Base score 7.3 · High

Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N


Access our resources on patching vulnerabilities