Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hrxx-hfqm-f933

Опубликовано: 19 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 3.3

Описание

The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated the calling user such that an unprivileged user is able to set metadata on a dataset indicating that the dataset has received properties from a zfs-recv(8) stream.

Any local user can set the internal ZFS metadata flag "$hasrecvd" on datasets via ZFS_IOC_SET_PROP.

The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated the calling user such that an unprivileged user is able to set metadata on a dataset indicating that the dataset has received properties from a zfs-recv(8) stream.

Any local user can set the internal ZFS metadata flag "$hasrecvd" on datasets via ZFS_IOC_SET_PROP.

EPSS

Процентиль: 2%
0.00119
Низкий

3.3 Low

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 3.3
nvd
около 1 месяца назад

The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated the calling user such that an unprivileged user is able to set metadata on a dataset indicating that the dataset has received properties from a zfs-recv(8) stream. Any local user can set the internal ZFS metadata flag "$hasrecvd" on datasets via ZFS_IOC_SET_PROP.

CVSS3: 3.3
fstec
3 месяца назад

Уязвимость обработчика ZFS_IOC_SET_PROP компонента OpenZFS ядра операционных систем FreeBSD, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

EPSS

Процентиль: 2%
0.00119
Низкий

3.3 Low

CVSS3

Дефекты

CWE-863