[Git][security-tracker-team/security-tracker][master] CVE-2026-79619/zfs-linux assigned

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 26 21:18:13 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
11e5a92a by Salvatore Bonaccorso at 2026-08-26T22:17:44+02:00
CVE-2026-79619/zfs-linux assigned

- - - - -


2 changed files:

- data/CVE/list
- data/DSA/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -407,8 +407,6 @@ CVE-2026-79902 (A flaw was found in the Seattle FilmWorks plugin in GIMP. When p
 	[bullseye] - gimp <not-affected> (Vulnerable code not present)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16582
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/fa9503bcc41e41ac0a5ae162a97486c79a7790ce
-CVE-2026-79619 (On Linux, several OpenZFS ioctl authorization checks accept a capabili ...)
-	TODO: check
 CVE-2026-78237 (Insufficient input validation in ABR allows a low-privileged user to i ...)
 	TODO: check
 CVE-2026-78236 (An insecure PIN derivation mechanism in ABR allows a low-privileged us ...)
@@ -4701,9 +4699,9 @@ CVE-2026-74584 (In the Linux kernel, the following vulnerability has been resolv
 	[bookworm] - linux 6.1.177-1
 	[bullseye] - linux 5.10.262-1
 	NOTE: https://git.kernel.org/linus/f6b079629becfa977f9c51fe53ad2e6dcc55ef44 (7.1-rc5)
-CVE-2026-XXXX [OpenZFS Linux open zpool manipulation and escapes via unprivileged userns]
+CVE-2026-79619 [OpenZFS Linux open zpool manipulation and escapes via unprivileged userns]
 	- zfs-linux 2.4.4-1
-	[trixie] - zfs-linux 2.3.9-0+deb13u1
+	NOTE: https://github.com/advisories/GHSA-mhf5-q8gw-qg9v
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/16/5
 	NOTE: https://github.com/openzfs/zfs/issues/18936
 	NOTE: https://github.com/openzfs/zfs/pull/18959


=====================================
data/DSA/list
=====================================
@@ -17,6 +17,7 @@
 	{CVE-2026-43804 CVE-2026-64713 CVE-2026-64719 CVE-2026-64728 CVE-2026-64730 CVE-2026-64757 CVE-2026-64783}
 	[trixie] - webkit2gtk 2.52.6-1~deb13u1
 [24 Aug 2026] DSA-6462-1 zfs-linux - security update
+	{CVE-2026-79619}
 	[trixie] - zfs-linux 2.3.9-0+deb13u1
 [23 Aug 2026] DSA-6461-1 thunderbird - security update
 	{CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74948 CVE-2026-74949 CVE-2026-74953 CVE-2026-74957 CVE-2026-74959 CVE-2026-74960 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74967 CVE-2026-74969 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74983 CVE-2026-74987 CVE-2026-74990}



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/11e5a92a657b90e9d9ad0b642fccd5f976fed110

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/11e5a92a657b90e9d9ad0b642fccd5f976fed110
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260826/42388859/attachment.htm>


More information about the debian-security-tracker-commits mailing list