DSA-6462-1 zfs-linux - security update
Erica Windisch reported several vulnerabilities in the Linux implementation of OpenZFS, a filesystem and volume manager. The administrative operations exposed by the /dev/zfs ioctl interface accepted the CAP_SYS_ADMIN capability in the calling process's own user namespace as authority over pools on the host, instead of requiring it in the initial user namespace. In addition, opening a vdev did not check that the caller was permitted to access the underlying device node or backing file. Since /dev/zfs is world-accessible and unprivileged user namespaces are enabled by default, a local user can take advantage of these flaws to administer pools on the host, to attach and write to devices they have no permission to access, and thereby to escalate privileges or cause a denial of service. The same flaws allow a process in a container to which /dev/zfs is exposed to act on the host storage stack. This update is based on the upstream 2.3.9 release, which also contains a number of fixes for data corruption, kernel panics and deadlocks. https://security-tracker.debian.org/tracker/DSA-6462-1
CSIRTS triage
- What
- Linux OpenZFS incorrectly validates user namespace authority and device access permissions on the /dev/zfs ioctl interface, allowing privilege escalation and denial of service.
- Who is affected
- Systems with unprivileged user namespaces enabled and /dev/zfs accessible to local users or containers.
- Urgency
- High — local privilege escalation and container escape; affects default Linux configurations with user namespaces enabled.
- Action
- Apply security updates for zfs-linux package addressing improper capability and device permission checks.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch zfs-linux
Get an email when a new zfs-linux advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00373.html
More from Debian Security Advisories
- unknownDSA-6464-1 erlang - security update2026-08-25
- unknownDSA-6465-1 openssl - security update2026-08-25
- unknownDSA-6466-1 linux - security update2026-08-25
- unknownDSA-6463-1 webkit2gtk - security update2026-08-24
- unknownDSA-6460-1 openjdk-25 - security update2026-08-23