Qlustar

Contact Info

Legal Information

Qlustar

Contact Info

Legal Information

[QSA-0925263]
OpenZFS vulnerability

Qlustar Security Advisory 0925263

September 25th, 2026


Summary:

OpenZFS vulnerabilities

Package(s)       : zfs-linux, zfs-modules-ql-generic,
                   qlustar-module-core-noble-amd64-14.1
Qlustar releases : 14
Affected versions: All versions prior to this update
Vulnerability    : Privilege escalation
Problem type     : local
Qlustar-specific : no
CVE Id(s)        : (see below)

Relevant to Qlustar 14

It was discovered that OpenZFS incorrectly handled authorization checks for certain ioctl operations on Linux. A local attacker could possibly use this issue to perform pool-administrative operations or access privileged information, resulting in an authorization bypass.

The fix of this vulnerability includes an upgrade to OpenZFS 2.3.9.

Update instructions:

The problem can be corrected by updating your system to the following or more recent package versions:

For Qlustar 14

zfs-linux                                  2.3.9-ql.1
zfs-modules-ql-generic                     2.3.9-ql.1+14-20
qlustar-module-core-noble-amd64-14.1       14.1.13-b589f1655