A public disclosure detailed eight OpenZFS on Linux vulnerabilities, tracked as OZ-1 through OZ-8, that weaken authorization checks and expose multiple import-time parser bugs. The report says pool-control ioctls improperly trust namespace-local CAP_SYS_ADMIN from unprivileged user namespaces and containers when /dev/zfs is accessible, allowing host pool operations from confined environments. Reported parser flaws include out-of-bounds reads and writes, a controlled heap overflow, a stack overflow, unbounded traversal, and a cache-destroy hang; OZ-4 was demonstrated as both a container-to-host-root exploit in a research VM and a reliable host-kernel denial-of-service path via malicious OCI images on TrueNAS SCALE and IncusOS.
Testing cited in the disclosure covered IncusOS, TrueNAS SCALE, Proxmox VE, and Unraid, while noting that a tested RHEL 10.2 configuration with OpenZFS 2.2.10 plus SELinux/STIG/FIPS blocked OZ-1 and OZ-2. The report said all OZ findings remained unfixed in upstream master as of 2026-07-24, except for OZ-7, which had an open contested pull request. Separately, Linux kernel documentation notes that kernel CVE assignment is conservative, generally tied to fixes already merged into supported stable trees, and excludes unsupported versions and distribution-specific issues, leaving downstream vendors and users to determine applicability and prioritize full released updates over cherry-picking individual fixes.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-16, Erica Windisch publicly disclosed a broad set of OpenZFS on Linux vulnerabilities via fulldisclosure and oss-sec. The disclosure covered authorization flaws and multiple parser/runtime bugs, including OZ-4 as a demonstrated container-to-host-root exploit path in a research VM.
The report says CERT was notified about the OpenZFS on Linux vulnerabilities on 2026-08-12. This marks the formal notification of the findings prior to public disclosure.
The disclosure states that all reported OZ findings were still unfixed in upstream OpenZFS master as of 2026-07-24, with only OZ-7 having an open contested pull request. This established the upstream remediation status at the time of the research.
Erica Windisch's research into OpenZFS on Linux vulnerabilities was conducted from 2026-07-17 through 2026-07-25, and the report was updated on 2026-07-25. The work identified authorization flaws and multiple parser/runtime issues labeled OZ-1 through OZ-8.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
linuxsecurity.com
Open sourceseclists.org
Open sourceseclists.org
Open sourcekernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.