Impact
The vulnerability allows an unprivileged local user to perform pool‑administrative operations, view pool event logs, and inject faults by exploiting an incorrect mapping of a capability inside an unprivileged user‑namespace to host‑elevated privilege. Based on the description, it is inferred that this weakness can be leveraged to fully control ZFS pools without root access, thus compromising confidentiality, integrity, and availability of stored data.
Affected Systems
The flaw affects the OpenZFS implementation on Linux. Based on the description, it is inferred that the affected kernel modules include the ZFS ioctl handlers that perform authorization checks. No explicit version range is listed in the advisory, but patch releases are available in the 2.2.11, 2.3.9, and 2.4.4 series.
Risk and Exploitability
The CVSS score of 7.3 classifies the issue as high severity. The exploit requires only local possession of /dev/zfs and the ability of the kernel to create unprivileged user namespaces, both of which are typically granted on a standard system. Based on the description, it is inferred that because no advanced privileges or external access are needed, an attacker can easily obtain the necessary conditions. Based on the description, it is also inferred that although EPSS is not reported and the vulnerability is not currently in the KEV catalog, its low attack barrier and high impact make it a significant risk for any system running OpenZFS on Linux.
OpenCVE Enrichment