CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

USN-8705-1: OpenZFS vulnerability

unknownCVE-2026-79619
It was discovered that OpenZFS incorrectly handled authorization checks for certain ioctl operations on Linux. A local attacker could possibly use this issue to perform pool-administrative operations or access privileged information, resulting in an authorization bypass.

CSIRTS triage

What
OpenZFS incorrectly handles authorization checks for certain ioctl operations on Linux, allowing unauthorized pool-administrative operations.
Who is affected
Local users on systems running OpenZFS on Linux.
Urgency
High urgency; local privilege escalation via authorization bypass affecting active deployments.
Action
Apply the security update from USN-8705-1 to patch CVE-2026-79619.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch OpenZFS

Get an email when a new OpenZFS advisory drops — max one per day, one-click unsubscribe.

Details

Source
Ubuntu Security Notices (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-08-31
Exploitation
Not in CISA KEV at last sync

Original advisory: https://ubuntu.com/security/notices/USN-8705-1

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-79619coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Ubuntu Security Notices