This bug was fixed in the package zfs-linux - 2.4.3-3ubuntu1
---------------
zfs-linux (2.4.3-3ubuntu1) stonking; urgency=medium
* Merge from Debian
- debian/control
- drop dependencies on "zfs-modules | zfs-dkms" such that all
packages can be installed in containers, on hosts that have zfs module
loaded
- adding systemd-cryptsetup as zfs-dracut dependency
- debian/libuutil3linux.symbols and debian/libzfs7linux.symbols
- removing __start_zfs_tunables and __stop_zfs_tunables as the extern
variables are not defined anywhere else
- debian/patches:
- adding
- ubuntu/0001-Revert-Revert-systemd-Use-non-absolute-paths-in-Exec.patch
- ubuntu/0002-Revert-etc-systemd-zfs-mount-generator-rewrite-in-C.patch
- ubuntu/4000-zsys-support.patch
- ubuntu/4001-dracut-Open-and-mount-luks-keystore.patch
- ubuntu/4100-disable-bpool-upgrade.patch
- ubuntu/zfs-mount-container-start.patch
- ubuntu/4510-silently-ignore-modprobe-failure.patch
- ubuntu/4751-suppress-types.patch
- ubuntu/fixup-abi.patch
- ubuntu/0003-enable-linux-experimental.patch
- ubuntu/0004-rename-sms-service.patch
- ubuntu/0005-Linux-7.2-zpl_super-convert-to-sget_fc.patch
- ubuntu/0006-ZTS-test-secpolicy_sys_config-correctly-limits-names.patch
- ubuntu/0007-ZTS-test-secpolicy_zinject-correctly-limits-namespac.patch
- ubuntu/0008-secpolicy_nfs-remove-not-used.patch
- ubuntu/0009-secpolicy_zinject-only-permit-a-global-zone-credenti.patch
- ubuntu/0010-secpolicy_sys_config-only-permit-a-global-zone-crede.patch
- ubuntu/0011-secpolicy_zfs-add-a-note-about-the-power-of-CAP_SYS_.patch
- debian/rules:
- enforce abi check on Ubuntu amd64
- debian/tests/:
- reduce testing to smoketest only
- Ubuntu Kernel regression testing covers zfs testsuite
- Drop depends on linux-headers-*.
- draid tests fail upstream, so marking failures as expected
to fail
* Fixes for unprivileged user access to pool operations (LP: #2164774)
- debian/patches:
- ubuntu/0006-ZTS-test-secpolicy_sys_config-correctly-limits-names.patch
- ubuntu/0007-ZTS-test-secpolicy_zinject-correctly-limits-namespac.patch
- ubuntu/0008-secpolicy_nfs-remove-not-used.patch
- ubuntu/0009-secpolicy_zinject-only-permit-a-global-zone-credenti.patch
- ubuntu/0010-secpolicy_sys_config-only-permit-a-global-zone-crede.patch
- ubuntu/0011-secpolicy_zfs-add-a-note-about-the-power-of-CAP_SYS_.patch
-- John Cabaj <[email protected]> Fri, 21 Aug 2026 10:24:17
-0500
** Changed in: zfs-linux (Ubuntu Stonking)
Status: In Progress => Fix Released
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2164774
Title:
OpenZFS Linux open zpool manipulation and escapes via unprivileged
userns
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/zfs-linux/+bug/2164774/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs