|
|
Log in / Subscribe / Register

Ubuntu alert USN-8705-2 (zfs-linux)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8705-2] OpenZFS vulnerability
Date:  Tue, 01 Sep 2026 00:09:43 +0000
Message-ID:  <E1x1C4N-0007dY-KQ@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8705-2 August 31, 2026 zfs-linux vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: OpenZFS could be made to run programs as an administrator. Software Description: - zfs-linux: OpenZFS file system for Linux Details: USN-8705-1 fixed vulnerabilities in OpenZFS. This update provides the corresponding fix for OpenZFS on Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. Original advisory details: It was discovered that OpenZFS incorrectly handled authorization checks for certain ioctl operations on Linux. A local attacker could possibly use this issue to perform pool-administrative operations or access privileged information, resulting in an authorization bypass. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS libuutil1linux 0.8.3-1ubuntu12.18+esm1 Available with Ubuntu Pro libzfs2linux 0.8.3-1ubuntu12.18+esm1 Available with Ubuntu Pro zfs-dkms 0.8.3-1ubuntu12.18+esm1 Available with Ubuntu Pro zfsutils-linux 0.8.3-1ubuntu12.18+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS libuutil1linux 0.7.5-1ubuntu16.12+esm1 Available with Ubuntu Pro libzfs2linux 0.7.5-1ubuntu16.12+esm1 Available with Ubuntu Pro zfs-dkms 0.7.5-1ubuntu16.12+esm1 Available with Ubuntu Pro zfsutils-linux 0.7.5-1ubuntu16.12+esm1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8705-2 https://ubuntu.com/security/notices/USN-8705-1 CVE-2026-79619


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmqWF28ACgkQcpJm3tlz hgG92Q//b3lJ9IOkxKVY4QSWpk665i2MSyItGW2q9yheaJdK/fV5KYLb1s93duy2 8PWMCXJfY8rr97x1ozsx7JRiD2/euTDrpuAt6y4D5uO+d3Fg9gGihPjw67S3U1jJ WdpBr6dkutliKi/oqjnMoQSORUyqVgd5Mcr4oN7CHYDhXtE0nM4NDuSRjbvmFl+O X4lUg6E7b/T2huFTPFaVyBI3Cna6pQMb7IyKHysGTAVViqeg0NQ6daF+RNYpfC9M +7IeN2rOJQ3Pjq35yJnGTu+I2zg6bYD8v+x3FKlLGPWaESEMygOi6F1h6ql0UDrp BQ0oqF4aA5AbcozF8WP7lYnUjdDEtkAa2pYcD8P83pqwH7ZWNS0mMpTnwOQPavzL FUZmHLtiR/pXy1pCVB/0wi2/no13XI2N+5rXxsfYO10kFcoM7u2Wjx7CnL2rPAgw YIaO42dG6d1xr7B5Q4m7mG3uVH2gpJ6qSXvpEfAezc+0h779Wy7Dxc5E3iIsYLrM mw9qrRV2F26TkCplSqU9AyMhMXIhLxU8R23uk0HeXDoXy4492DuSFnMzIAwwLa+Z Bqvh/6TeXvfgEQ1te4UdMMJyCI1Mjd3N3sIqfl35YuKRwt9oGvX4KiBmNi+gR0kf qbTsHYEdErpNCokPqPml0BIYg2L6XfE9PmXbMGLoAXyH1Iu13tI= =NZkr -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds