OpenZFS Authorization Bypass Vulnerability Affects Ubuntu LTS Releases
A critical flaw in OpenZFS allowed local attackers to bypass authorization controls. Patches are now available for Ubuntu 18.04 and 20.04 LTS.
TL;DR
- OpenZFS had an authorization bypass flaw affecting certain ioctl operations.
- Local attackers could gain admin-level access or view privileged data.
- Ubuntu released patches in USN-8705-1 and USN-8705-2 for supported LTS versions.
- Organizations using ZFS on Ubuntu should apply updates immediately.
- No active exploitation has been reported at this time.
A high-severity vulnerability has been identified in OpenZFS that impacts Ubuntu Long Term Support (LTS) systems. The issue stems from improper handling of authorization checks during specific ioctl operations, potentially allowing unauthorized users to perform administrative actions or access sensitive information.
Canonical has addressed the flaw through two security notices—USN-8705-1 and USN-8705-2—which provide fixes tailored to different Ubuntu versions. Users running ZFS-based storage configurations should prioritize applying these updates to mitigate risks associated with privilege escalation.
Vulnerability Details
- The flaw affects OpenZFS on Linux systems where ioctl operations lack proper permission validation.
- An unprivileged local user could exploit this to execute pool-administrative commands.
- Sensitive data normally restricted to root or authorized roles may become accessible without credentials.
- The vulnerability does not require network access, limiting exposure to already-authenticated users.
Affected Systems and Fixes
- Ubuntu 18.04 LTS and 20.04 LTS are impacted and have received targeted patches.
- Patches were delivered via USN-8705-1 (general fix) and USN-8705-2 (specific to older LTS releases).
- Systems utilizing ZFS for file storage or volume management should be updated immediately.
- Administrators can verify patch status by checking installed package versions for zfs-linux.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.