<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – OpenZFS</title>
  <link>https://cvedaily.com/pages/tags/openzfs.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/openzfs.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – OpenZFS</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:08 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2023-49298 – OpenZFS through 2.1.13 and 2.2.x through 2.2.1, in certain scenarios involving a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49298</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49298</guid>
    <pubDate>Fri, 24 Nov 2023 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-49298</strong></p>
  <p>OpenZFS through 2.1.13 and 2.2.x through 2.2.1, in certain scenarios involving applications that try to rely on efficient copying of file data, can replace file contents with zero-valued bytes and thus potentially disable security mechanisms. NOTE: this issue is not always security related, but can be security related in realistic situations. A possible example is cp, from a recent GNU Core Utili…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49298">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-20001 – An issue was discovered in OpenZFS through 2.0.3. When an NFS share is exported ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-20001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-20001</guid>
    <pubDate>Fri, 12 Feb 2021 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-20001</strong></p>
  <p>An issue was discovered in OpenZFS through 2.0.3. When an NFS share is exported to IPv6 addresses via the sharenfs feature, there is a silent failure to parse the IPv6 address data, and access is allowed to everyone. IPv6 restrictions from the configuration are not applied.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-20001">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-24717 – OpenZFS before 2.0.0-rc1, when used on FreeBSD, misinterprets group permissions ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24717</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24717</guid>
    <pubDate>Thu, 27 Aug 2020 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-24717</strong></p>
  <p>OpenZFS before 2.0.0-rc1, when used on FreeBSD, misinterprets group permissions as user permissions, as demonstrated by mode 0770 being equivalent to mode 0777.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24717">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-24716 – OpenZFS before 2.0.0-rc1, when used on FreeBSD, allows execute permissions for a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24716</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24716</guid>
    <pubDate>Thu, 27 Aug 2020 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-24716</strong></p>
  <p>OpenZFS before 2.0.0-rc1, when used on FreeBSD, allows execute permissions for all directories.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24716">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
