Ubuntu OpenZFS Vulnerability Allows Admin Access Bypass

Ubuntu OpenZFS Vulnerability Allows Admin Access Bypass

First seen 31 Aug 2026, 16:30 UTC UbuntuLinuxsecurity 45.0

Article Content

Browse articles
ThreatCluster

A vulnerability in OpenZFS was discovered, which incorrectly handled authorization checks for certain ioctl operations on Linux. This flaw could allow a local attacker to perform pool-administrative operations or access privileged information, leading to an authorization bypass. The affected systems include Ubuntu 26.04 LTS, 24.04 LTS, and 22.04 LTS. The vulnerability is identified as CVE-2026-8705-1. Users are advised to update their systems to specific package versions to mitigate the risk. After applying the updates, a system reboot is necessary to implement the changes. The issue was reported on August 31, 2026, and is currently not known to be actively exploited in the wild.

Key Points: • OpenZFS vulnerability allows local admin access bypass. • Affected systems include Ubuntu 26.04, 24.04, and 22.04 LTS. • Users must update and reboot their systems to mitigate the risk.

Timeline

2026-08-31
OpenZFS vulnerability disclosed
A flaw in OpenZFS was identified, allowing local attackers to bypass authorization checks.
Linuxsecurity
2026-08-31
Ubuntu Security Notice USN-8705-1 issued
Ubuntu released a security notice detailing the OpenZFS vulnerability and recommended updates.
Ubuntu