A local user with the "userused" delegated ZFS permission can trigger a kernel heap overflow via the ZFS_IOC_USERSPACE_MANY ioctl, potentially escalating privileges.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 19 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 19 Aug 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Freebsd
Freebsd freebsd |
|
| Vendors & Products |
Freebsd
Freebsd freebsd |
Wed, 19 Aug 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated a 64-bit output buffer size to a 32-bit integer for the kernel allocation, but used the original 64-bit size as the buffer limit when writing records. A local user with the "userused" delegated ZFS permission can trigger a kernel heap overflow via the ZFS_IOC_USERSPACE_MANY ioctl, potentially escalating privileges. | |
| Title | Kernel heap overflow in ZFS_IOC_USERSPACE_MANY ioctl | |
| Weaknesses | CWE-122 | |
| References |
|
Status: PUBLISHED
Assigner: freebsd
Published:
Updated: 2026-08-19T12:16:35.367Z
Reserved: 2026-05-29T20:24:28.616Z
Link: CVE-2026-49429
No data.
Status : Received
Published: 2026-08-19T06:17:42.513
Modified: 2026-08-19T13:17:46.030
Link: CVE-2026-49429
No data.
OpenCVE Enrichment
Updated: 2026-08-19T20:00:05Z