[Bug 295485] need a way to block zfs.ko from being autoloaded by tools like puppet and facter (FatGID Vuln / CVE-2026-45250)
[email protected] Mon, 22 Jun 2026 02:00:17 +0000
| Newsgroups | gmane.os.freebsd.devel.file-systems |
|---|---|
| Message-ID | <[email protected]/bugzilla/> |
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=295485 --- Comment #37 from Mark Millard <[email protected]> --- (In reply to Allan Jude from comment #35) Well, ignore any interpretations I have about what may be more likely to be accepted vs. not: One of the folks upstream commented about preferring your opt-in/opt-out style of handling. Something I do not know is what is the FreeBSD OS intent for mixing and machine just one of: filesystems/openzfs-kmod vs. filesystems/openzfs with the system variant of the other. Similarly for mixing and matching different versions of filesystems/openzfs-kmod and filesystems/openzfs (no use of the system ones). One of the upstream worries is about supporting such mix and match combinations where the kernel module and the user space utilities do not match. Seems like openzfs expects to support such fairly generally --but even now the FreeBSD system zfs is not set up to work the way intended for that --and that is part of why zpool upgrade -v and zfs upgrade -v are not using zfs.ko as things are. -- You are receiving this mail because: You are the assignee for the bug.