September 25th, 2026
OpenZFS vulnerabilities
Package(s) : zfs-linux, zfs-modules-ql-generic,
qlustar-module-core-noble-amd64-14.1
Qlustar releases : 14
Affected versions: All versions prior to this update
Vulnerability : Privilege escalation
Problem type : local
Qlustar-specific : no
CVE Id(s) : (see below)
It was discovered that OpenZFS incorrectly handled authorization checks for certain ioctl operations on Linux. A local attacker could possibly use this issue to perform pool-administrative operations or access privileged information, resulting in an authorization bypass.
The fix of this vulnerability includes an upgrade to OpenZFS 2.3.9.
The problem can be corrected by updating your system to the following or more recent package versions:
zfs-linux 2.3.9-ql.1
zfs-modules-ql-generic 2.3.9-ql.1+14-20
qlustar-module-core-noble-amd64-14.1 14.1.13-b589f1655