Debian dsa-6462 : libnvpair3linux - security update

high Nessus Plugin ID 339127

Synopsis

The remote Debian host is missing a security-related update.

Description

The remote Debian 13 host has packages installed that are affected by a vulnerability as referenced in the dsa-6462 advisory.

- ------------------------------------------------------------------------- Debian Security Advisory DSA-6462-1 [email protected] https://www.debian.org/security/ Aron Xu August 24, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : zfs-linux

Erica Windisch reported several vulnerabilities in the Linux implementation of OpenZFS, a filesystem and volume manager.

The administrative operations exposed by the /dev/zfs ioctl interface accepted the CAP_SYS_ADMIN capability in the calling process's own user namespace as authority over pools on the host, instead of requiring it in the initial user namespace. In addition, opening a vdev did not check that the caller was permitted to access the underlying device node or backing file. Since /dev/zfs is world-accessible and unprivileged user namespaces are enabled by default, a local user can take advantage of these flaws to administer pools on the host, to attach and write to devices they have no permission to access, and thereby to escalate privileges or cause a denial of service. The same flaws allow a process in a container to which /dev/zfs is exposed to act on the host storage stack.

This update is based on the upstream 2.3.9 release, which also contains a number of fixes for data corruption, kernel panics and deadlocks.

For the stable distribution (trixie), this problem has been fixed in version 2.3.9-0+deb13u1.

We recommend that you upgrade your zfs-linux packages.

For the detailed security status of zfs-linux please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/zfs-linux

Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/

Mailing list: [email protected]

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade the libnvpair3linux packages.

See Also

https://packages.debian.org/source/trixie/zfs-linux

https://security-tracker.debian.org/tracker/source-package/zfs-linux

Plugin Details

Severity: High

ID: 339127

File Name: debian_DSA-6462.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/24/2026

Updated: 8/24/2026

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Vulnerability Information

CPE: cpe:/o:debian:debian_linux:13.0, p-cpe:/a:debian:debian_linux:libnvpair3linux, p-cpe:/a:debian:debian_linux:libpam-zfs, p-cpe:/a:debian:debian_linux:libuutil3linux, p-cpe:/a:debian:debian_linux:libzfs6linux, p-cpe:/a:debian:debian_linux:libzfsbootenv1linux, p-cpe:/a:debian:debian_linux:libzfslinux-dev, p-cpe:/a:debian:debian_linux:libzpool6linux, p-cpe:/a:debian:debian_linux:python3-pyzfs, p-cpe:/a:debian:debian_linux:pyzfs-doc, p-cpe:/a:debian:debian_linux:zfs-dkms, p-cpe:/a:debian:debian_linux:zfs-dracut, p-cpe:/a:debian:debian_linux:zfs-initramfs, p-cpe:/a:debian:debian_linux:zfs-test, p-cpe:/a:debian:debian_linux:zfs-zed, p-cpe:/a:debian:debian_linux:zfsutils-linux

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 8/24/2026

Vulnerability Publication Date: 8/24/2026