{"id":"DEBIAN-CVE-2026-79619","details":"On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg create, import, destroy), pool event log access (zpool events) and fault injection (zinject). Exploiting the problem requires only that the local user is permitted to open /dev/zfs (governed by local device permissions) and that the kernel permits unprivileged user namespace creation. No prior access to the target pool or its underlying devices is needed.","modified":"2026-09-14T17:03:49.408272061Z","published":"2026-08-26T13:19:24.003Z","upstream":["CVE-2026-79619"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-79619"}],"affected":[{"package":{"name":"zfs-linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/zfs-linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.6.5.10-1","0.6.5.11-1","0.6.5.11-1~bpo8+1","0.6.5.11-1~bpo9+1","0.6.5.5-1","0.6.5.6-1","0.6.5.6-2","0.6.5.7-1","0.6.5.7-2","0.6.5.7-2~bpo8+1","0.6.5.8-1","0.6.5.8-1~bpo8+1","0.6.5.8-2","0.6.5.8-2~bpo8+1","0.6.5.8-3","0.6.5.9-1","0.6.5.9-2","0.6.5.9-2~bpo8+1","0.6.5.9-3","0.6.5.9-4","0.6.5.9-5","0.6.5.9-5+sparc64","0.6.5.9-5~bpo8+1","0.7.11-1","0.7.11-1~bpo8+1","0.7.11-1~bpo9+1","0.7.11-2","0.7.11-3","0.7.12-1","0.7.12-1~bpo9+1","0.7.12-2","0.7.12-3","0.7.12-4","0.7.12-5","0.7.13-1","0.7.13-1~bpo10+1","0.7.13-1~bpo9+1","0.7.3-1","0.7.3-2","0.7.3-3","0.7.3-3~bpo8+1","0.7.3-3~bpo9+1","0.7.4-1","0.7.4-1~bpo8+1","0.7.4-1~bpo9+1","0.7.5-1","0.7.5-1~bpo9+1","0.7.6-1","0.7.6-1~bpo8+1","0.7.6-1~bpo9+1","0.7.9-0.1","0.7.9-1","0.7.9-2","0.7.9-3","0.7.9-3~bpo8+1","0.7.9-3~bpo9+1","0.8.0-1","0.8.0-2","0.8.0~rc3-1","0.8.0~rc4-1","0.8.1-1","0.8.1-2","0.8.1-3","0.8.1-4","0.8.1-4~bpo10+1","0.8.2-1","0.8.2-2","0.8.2-2~bpo10+1","0.8.2-3","0.8.2-3~bpo10+1","0.8.2-4","0.8.2-5","0.8.3-1","0.8.3-1~bpo10+1","0.8.3-2","0.8.4-1","0.8.4-1~bpo10+1","0.8.4-2","0.8.4-2~bpo10+1","0.8.5-1","0.8.5-2","0.8.5-2~bpo10+1","0.8.5-3","0.8.5-3~bpo10+1","0.8.6-1","0.8.6-1~bpo10+1","2.0.0-1~exp1","2.0.1-1","2.0.1-1~exp1","2.0.1-2","2.0.1-3","2.0.2-1","2.0.2-1~bpo10+1","2.0.3-1","2.0.3-1~bpo10+1","2.0.3-2","2.0.3-3","2.0.3-4","2.0.3-5","2.0.3-6","2.0.3-7","2.0.3-8","2.0.3-8~bpo10+1","2.0.3-9","2.0.3-9~bpo10+1","2.0.6-1","2.0.6-1~bpo10+1","2.0.6-1~bpo11+1","2.0.6-2","2.0.7-1~bpo10+1","2.1.1-1","2.1.1-2","2.1.1-3","2.1.11-1","2.1.11-1+deb12u1","2.1.11-1~bpo11+1","2.1.12-1","2.1.12-2","2.1.12-2~bpo12+1","2.1.13-1","2.1.13-1~bpo11+1","2.1.13-1~bpo12+1","2.1.13-2","2.1.13-2~bpo11+1","2.1.13-2~bpo12+1","2.1.14-1","2.1.14-1~bpo11+1","2.1.14-1~bpo12+1","2.1.2-1","2.1.2-1~bpo11+1","2.1.4-1","2.1.4-1~bpo11+1","2.1.5-1","2.1.5-1~bpo11+1","2.1.6-1","2.1.6-2","2.1.6-3","2.1.6-3~bpo11+1","2.1.7-1","2.1.7-1~bpo11+1","2.1.7-2","2.1.8-1","2.1.9-1","2.1.9-1~bpo11+1","2.1.9-2","2.1.9-3","2.1.9-3~bpo11+1","2.1.9-4","2.2.0-1~exp1","2.2.1-1~exp1","2.2.1-1~exp2","2.2.2-1","2.2.2-1~exp1","2.2.2-2","2.2.2-3","2.2.2-3~bpo12+1","2.2.2-4","2.2.2-4~bpo12+1","2.2.2-5~exp1","2.2.2-5~exp2","2.2.2-5~exp3","2.2.3-1","2.2.3-1~bpo12+1","2.2.3-2","2.2.3-2~bpo12+1","2.2.4-1","2.2.4-1~bpo12+1","2.2.4-2","2.2.5-1","2.2.5-1~bpo12+1","2.2.6-1","2.2.6-1~bpo12+1","2.2.6-1~bpo12+2","2.2.6-1~bpo12+3","2.2.6-2","2.2.7-1","2.2.7-1~bpo12+1","2.2.7-2","2.3.0-1","2.3.0-1~exp1","2.3.0-2","2.3.0-2~exp1","2.3.0~rc5-1~exp1","2.3.0~rc5-1~exp1.1","2.3.1-1","2.3.1-1~bpo12+1","2.3.2-1","2.3.2-2","2.3.2-2~bpo12+1","2.3.2-2~bpo12+2","2.3.3-1","2.3.3-1~bpo13+1","2.3.4-1","2.3.4-1~bpo13+1","2.3.4~git20250812.3b64a96-1","2.3.5-1","2.3.5-2","2.3.5-2~bpo13+1","2.4.0-1","2.4.0-1~bpo13+1","2.4.0-1~exp1","2.4.1-1","2.4.1-1~bpo13+1","2.4.2-1","2.4.2-1~bpo13+1","2.4.2-2","2.4.3-1","2.4.3-1~bpo13+1","2.4.3-2","2.4.3-2~bpo13+1","2.4.3-3","2.4.4-1","2.4.4-1~bpo13+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-79619.json"}},{"package":{"name":"zfs-linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/zfs-linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.9-0+deb13u1"}]}],"versions":["0.6.5.10-1","0.6.5.11-1","0.6.5.11-1~bpo8+1","0.6.5.11-1~bpo9+1","0.6.5.5-1","0.6.5.6-1","0.6.5.6-2","0.6.5.7-1","0.6.5.7-2","0.6.5.7-2~bpo8+1","0.6.5.8-1","0.6.5.8-1~bpo8+1","0.6.5.8-2","0.6.5.8-2~bpo8+1","0.6.5.8-3","0.6.5.9-1","0.6.5.9-2","0.6.5.9-2~bpo8+1","0.6.5.9-3","0.6.5.9-4","0.6.5.9-5","0.6.5.9-5+sparc64","0.6.5.9-5~bpo8+1","0.7.11-1","0.7.11-1~bpo8+1","0.7.11-1~bpo9+1","0.7.11-2","0.7.11-3","0.7.12-1","0.7.12-1~bpo9+1","0.7.12-2","0.7.12-3","0.7.12-4","0.7.12-5","0.7.13-1","0.7.13-1~bpo10+1","0.7.13-1~bpo9+1","0.7.3-1","0.7.3-2","0.7.3-3","0.7.3-3~bpo8+1","0.7.3-3~bpo9+1","0.7.4-1","0.7.4-1~bpo8+1","0.7.4-1~bpo9+1","0.7.5-1","0.7.5-1~bpo9+1","0.7.6-1","0.7.6-1~bpo8+1","0.7.6-1~bpo9+1","0.7.9-0.1","0.7.9-1","0.7.9-2","0.7.9-3","0.7.9-3~bpo8+1","0.7.9-3~bpo9+1","0.8.0-1","0.8.0-2","0.8.0~rc3-1","0.8.0~rc4-1","0.8.1-1","0.8.1-2","0.8.1-3","0.8.1-4","0.8.1-4~bpo10+1","0.8.2-1","0.8.2-2","0.8.2-2~bpo10+1","0.8.2-3","0.8.2-3~bpo10+1","0.8.2-4","0.8.2-5","0.8.3-1","0.8.3-1~bpo10+1","0.8.3-2","0.8.4-1","0.8.4-1~bpo10+1","0.8.4-2","0.8.4-2~bpo10+1","0.8.5-1","0.8.5-2","0.8.5-2~bpo10+1","0.8.5-3","0.8.5-3~bpo10+1","0.8.6-1","0.8.6-1~bpo10+1","2.0.0-1~exp1","2.0.1-1","2.0.1-1~exp1","2.0.1-2","2.0.1-3","2.0.2-1","2.0.2-1~bpo10+1","2.0.3-1","2.0.3-1~bpo10+1","2.0.3-2","2.0.3-3","2.0.3-4","2.0.3-5","2.0.3-6","2.0.3-7","2.0.3-8","2.0.3-8~bpo10+1","2.0.3-9","2.0.3-9~bpo10+1","2.0.6-1","2.0.6-1~bpo10+1","2.0.6-1~bpo11+1","2.0.6-2","2.0.7-1~bpo10+1","2.1.1-1","2.1.1-2","2.1.1-3","2.1.11-1","2.1.11-1~bpo11+1","2.1.12-1","2.1.12-2","2.1.12-2~bpo12+1","2.1.13-1","2.1.13-1~bpo11+1","2.1.13-1~bpo12+1","2.1.13-2","2.1.13-2~bpo11+1","2.1.13-2~bpo12+1","2.1.14-1","2.1.14-1~bpo11+1","2.1.14-1~bpo12+1","2.1.2-1","2.1.2-1~bpo11+1","2.1.4-1","2.1.4-1~bpo11+1","2.1.5-1","2.1.5-1~bpo11+1","2.1.6-1","2.1.6-2","2.1.6-3","2.1.6-3~bpo11+1","2.1.7-1","2.1.7-1~bpo11+1","2.1.7-2","2.1.8-1","2.1.9-1","2.1.9-1~bpo11+1","2.1.9-2","2.1.9-3","2.1.9-3~bpo11+1","2.1.9-4","2.2.0-1~exp1","2.2.1-1~exp1","2.2.1-1~exp2","2.2.2-1","2.2.2-1~exp1","2.2.2-2","2.2.2-3","2.2.2-3~bpo12+1","2.2.2-4","2.2.2-4~bpo12+1","2.2.2-5~exp1","2.2.2-5~exp2","2.2.2-5~exp3","2.2.3-1","2.2.3-1~bpo12+1","2.2.3-2","2.2.3-2~bpo12+1","2.2.4-1","2.2.4-1~bpo12+1","2.2.4-2","2.2.5-1","2.2.5-1~bpo12+1","2.2.6-1","2.2.6-1~bpo12+1","2.2.6-1~bpo12+2","2.2.6-1~bpo12+3","2.2.6-2","2.2.7-1","2.2.7-1~bpo12+1","2.2.7-2","2.3.0-1","2.3.0-1~exp1","2.3.0-2","2.3.0-2~exp1","2.3.0~rc5-1~exp1","2.3.0~rc5-1~exp1.1","2.3.1-1","2.3.1-1~bpo12+1","2.3.2-1","2.3.2-2","2.3.2-2~bpo12+1","2.3.2-2~bpo12+2","2.3.3-1","2.3.3-1~bpo13+1","2.3.4-1","2.3.4-1~bpo13+1","2.3.4~git20250812.3b64a96-1","2.3.5-1","2.3.5-2","2.3.5-2~bpo13+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-79619.json"}},{"package":{"name":"zfs-linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/zfs-linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.4-1"}]}],"versions":["0.6.5.10-1","0.6.5.11-1","0.6.5.11-1~bpo8+1","0.6.5.11-1~bpo9+1","0.6.5.5-1","0.6.5.6-1","0.6.5.6-2","0.6.5.7-1","0.6.5.7-2","0.6.5.7-2~bpo8+1","0.6.5.8-1","0.6.5.8-1~bpo8+1","0.6.5.8-2","0.6.5.8-2~bpo8+1","0.6.5.8-3","0.6.5.9-1","0.6.5.9-2","0.6.5.9-2~bpo8+1","0.6.5.9-3","0.6.5.9-4","0.6.5.9-5","0.6.5.9-5+sparc64","0.6.5.9-5~bpo8+1","0.7.11-1","0.7.11-1~bpo8+1","0.7.11-1~bpo9+1","0.7.11-2","0.7.11-3","0.7.12-1","0.7.12-1~bpo9+1","0.7.12-2","0.7.12-3","0.7.12-4","0.7.12-5","0.7.13-1","0.7.13-1~bpo10+1","0.7.13-1~bpo9+1","0.7.3-1","0.7.3-2","0.7.3-3","0.7.3-3~bpo8+1","0.7.3-3~bpo9+1","0.7.4-1","0.7.4-1~bpo8+1","0.7.4-1~bpo9+1","0.7.5-1","0.7.5-1~bpo9+1","0.7.6-1","0.7.6-1~bpo8+1","0.7.6-1~bpo9+1","0.7.9-0.1","0.7.9-1","0.7.9-2","0.7.9-3","0.7.9-3~bpo8+1","0.7.9-3~bpo9+1","0.8.0-1","0.8.0-2","0.8.0~rc3-1","0.8.0~rc4-1","0.8.1-1","0.8.1-2","0.8.1-3","0.8.1-4","0.8.1-4~bpo10+1","0.8.2-1","0.8.2-2","0.8.2-2~bpo10+1","0.8.2-3","0.8.2-3~bpo10+1","0.8.2-4","0.8.2-5","0.8.3-1","0.8.3-1~bpo10+1","0.8.3-2","0.8.4-1","0.8.4-1~bpo10+1","0.8.4-2","0.8.4-2~bpo10+1","0.8.5-1","0.8.5-2","0.8.5-2~bpo10+1","0.8.5-3","0.8.5-3~bpo10+1","0.8.6-1","0.8.6-1~bpo10+1","2.0.0-1~exp1","2.0.1-1","2.0.1-1~exp1","2.0.1-2","2.0.1-3","2.0.2-1","2.0.2-1~bpo10+1","2.0.3-1","2.0.3-1~bpo10+1","2.0.3-2","2.0.3-3","2.0.3-4","2.0.3-5","2.0.3-6","2.0.3-7","2.0.3-8","2.0.3-8~bpo10+1","2.0.3-9","2.0.3-9~bpo10+1","2.0.6-1","2.0.6-1~bpo10+1","2.0.6-1~bpo11+1","2.0.6-2","2.0.7-1~bpo10+1","2.1.1-1","2.1.1-2","2.1.1-3","2.1.11-1","2.1.11-1~bpo11+1","2.1.12-1","2.1.12-2","2.1.12-2~bpo12+1","2.1.13-1","2.1.13-1~bpo11+1","2.1.13-1~bpo12+1","2.1.13-2","2.1.13-2~bpo11+1","2.1.13-2~bpo12+1","2.1.14-1","2.1.14-1~bpo11+1","2.1.14-1~bpo12+1","2.1.2-1","2.1.2-1~bpo11+1","2.1.4-1","2.1.4-1~bpo11+1","2.1.5-1","2.1.5-1~bpo11+1","2.1.6-1","2.1.6-2","2.1.6-3","2.1.6-3~bpo11+1","2.1.7-1","2.1.7-1~bpo11+1","2.1.7-2","2.1.8-1","2.1.9-1","2.1.9-1~bpo11+1","2.1.9-2","2.1.9-3","2.1.9-3~bpo11+1","2.1.9-4","2.2.0-1~exp1","2.2.1-1~exp1","2.2.1-1~exp2","2.2.2-1","2.2.2-1~exp1","2.2.2-2","2.2.2-3","2.2.2-3~bpo12+1","2.2.2-4","2.2.2-4~bpo12+1","2.2.2-5~exp1","2.2.2-5~exp2","2.2.2-5~exp3","2.2.3-1","2.2.3-1~bpo12+1","2.2.3-2","2.2.3-2~bpo12+1","2.2.4-1","2.2.4-1~bpo12+1","2.2.4-2","2.2.5-1","2.2.5-1~bpo12+1","2.2.6-1","2.2.6-1~bpo12+1","2.2.6-1~bpo12+2","2.2.6-1~bpo12+3","2.2.6-2","2.2.7-1","2.2.7-1~bpo12+1","2.2.7-2","2.3.0-1","2.3.0-1~exp1","2.3.0-2","2.3.0-2~exp1","2.3.0~rc5-1~exp1","2.3.0~rc5-1~exp1.1","2.3.1-1","2.3.1-1~bpo12+1","2.3.2-1","2.3.2-2","2.3.2-2~bpo12+1","2.3.2-2~bpo12+2","2.3.3-1","2.3.3-1~bpo13+1","2.3.4-1","2.3.4-1~bpo13+1","2.3.4~git20250812.3b64a96-1","2.3.5-1","2.3.5-2","2.3.5-2~bpo13+1","2.4.0-1","2.4.0-1~bpo13+1","2.4.0-1~exp1","2.4.1-1","2.4.1-1~bpo13+1","2.4.2-1","2.4.2-1~bpo13+1","2.4.2-2","2.4.3-1","2.4.3-1~bpo13+1","2.4.3-2","2.4.3-2~bpo13+1","2.4.3-3","2.4.4-1~bpo13+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-79619.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}]}