SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-49430

HIGH · CVSS 7.8 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability allows a local user with "receive" delegated ZFS permission to exploit the ZFS_IOC_RECV_NEW ioctl, leading to kernel memory corruption through a crafted receive stream in heal mode. This could potentially result in system instability or unauthorized access to sensitive information. Organizations utilizing ZFS should prioritize addressing this issue to mitigate risks associated with local user exploitation.

CVE
CVE-2026-49430
Severity
HIGH
CVSS
7.8
EPSS
0.16%

Original NVD Description

The ZFS_IOC_RECV_NEW ioctl, in the heal receive path, similarly truncated a 64-bit payload size to a 32-bit integer for allocation, then used the original 64-bit size as the length for a byteswap operation. A local user with the "receive" delegated ZFS permission can trigger kernel memory corruption via ZFS_IOC_RECV_NEW by sending a crafted receive stream in heal mode.

Related CVEs

Other vulnerabilities affecting the same vendor(s)