CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

DSA-6462-1 zfs-linux - security update

unknown
Erica Windisch reported several vulnerabilities in the Linux implementation of OpenZFS, a filesystem and volume manager. The administrative operations exposed by the /dev/zfs ioctl interface accepted the CAP_SYS_ADMIN capability in the calling process's own user namespace as authority over pools on the host, instead of requiring it in the initial user namespace. In addition, opening a vdev did not check that the caller was permitted to access the underlying device node or backing file. Since /dev/zfs is world-accessible and unprivileged user namespaces are enabled by default, a local user can take advantage of these flaws to administer pools on the host, to attach and write to devices they have no permission to access, and thereby to escalate privileges or cause a denial of service. The same flaws allow a process in a container to which /dev/zfs is exposed to act on the host storage stack. This update is based on the upstream 2.3.9 release, which also contains a number of fixes for data corruption, kernel panics and deadlocks. https://security-tracker.debian.org/tracker/DSA-6462-1

CSIRTS triage

What
Linux OpenZFS incorrectly validates user namespace authority and device access permissions on the /dev/zfs ioctl interface, allowing privilege escalation and denial of service.
Who is affected
Systems with unprivileged user namespaces enabled and /dev/zfs accessible to local users or containers.
Urgency
High — local privilege escalation and container escape; affects default Linux configurations with user namespaces enabled.
Action
Apply security updates for zfs-linux package addressing improper capability and device permission checks.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch zfs-linux

Get an email when a new zfs-linux advisory drops — max one per day, one-click unsubscribe.

Details

Source
Debian Security Advisories (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-08-24
Exploitation
Not in CISA KEV at last sync

Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00373.html

More from Debian Security Advisories