[DSA 6462-1] zfs-linux security update
Aron Xu <[email protected]>
| Newsgroups | gmane.linux.debian.user.security.announce |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6462-1 [email protected] https://www.debian.org/security/ Aron Xu August 24, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : zfs-linux Erica Windisch reported several vulnerabilities in the Linux implementation of OpenZFS, a filesystem and volume manager. The administrative operations exposed by the /dev/zfs ioctl interface accepted the CAP_SYS_ADMIN capability in the calling process's own user namespace as authority over pools on the host, instead of requiring it in the initial user namespace. In addition, opening a vdev did not check that the caller was permitted to access the underlying device node or backing file. Since /dev/zfs is world-accessible and unprivileged user namespaces are enabled by default, a local user can take advantage of these flaws to administer pools on the host, to attach and write to devices they have no permission to access, and thereby to escalate privileges or cause a denial of service. The same flaws allow a process in a container to which /dev/zfs is exposed to act on the host storage stack. This update is based on the upstream 2.3.9 release, which also contains a number of fixes for data corruption, kernel panics and deadlocks. For the stable distribution (trixie), this problem has been fixed in version 2.3.9-0+deb13u1. We recommend that you upgrade your zfs-linux packages. For the detailed security status of zfs-linux please refer to its security tracker page at: https://security-tracker.debian.org/tracker/zfs-linux Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: [email protected] -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEExq6D0hxncEPaPayX+GQ1dHE8m64FAmqMYwAACgkQ+GQ1dHE8 m66Z0ggA5bYi6PHusvPlFQfUWVEC+AWeivXsGWKi7shYmJVAFQ3lBugZFJYigR62 L8+8nmXM51rCwbbQH3oJVTO9+jy1Ki4+9sQD5OJAmyy4c3SKkKIkQDx+7aibFxua SEl4XpxMHNuCl2f62S47VX9b2dnUk2shGTrfVbWAdhLfakjMuiSrcr8cis/nZ5U3 jVrEDoumSiSN0KN3PAQtJXlhcaFLKrsA/EH3DzFjai6ql73/BD9foOnl4zQbP/f7 e/nKrojuEL8dfOmJ+g1yF65hFym/SRFNWJxVThBSfWOVi3dtsi6qZUcs/+cnMvkF DSIJ000d5lYCUxxk1SANtoMGD6aRYQ== =JDzK -----END PGP SIGNATURE-----