OpenZFS is a widely embedded storage and filesystem technology deployed across enterprise infrastructure, data centers, and networked storage systems despite a narrow product footprint. Its observed vulnerabilities concentrate on authorization and access-control issues—including user-controlled key bypasses, default permission misconfigurations, and improper access-control logic—that reflect the authentication and privilege boundaries inherent to a shared storage platform. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openzfs over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-24716HIGH OpenZFS before 2.0.0-rc1, when used on FreeBSD, allows execute permissions for all directories. | Aug 27, 2020 | 7.8 | 25 | NO | NO |
CVE-2020-24717HIGH OpenZFS before 2.0.0-rc1, when used on FreeBSD, misinterprets group permissions as user permissions, as demonstrated by mode 0770 being equivalent to mode 0777. | Aug 27, 2020 | 7.8 | 24 | NO | NO |
CVE-2023-49298HIGH OpenZFS through 2.1.13 and 2.2.x through 2.2.1, in certain scenarios involving applications that try to rely on efficient copying of file data, can replace file contents with zero- | Nov 24, 2023 | 7.5 | 22 | NO | NO |
CVE-2013-20001HIGH An issue was discovered in OpenZFS through 2.0.3. When an NFS share is exported to IPv6 addresses via the sharenfs feature, there is a silent failure to parse the IPv6 address data | Feb 12, 2021 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openzfs.
Media articles that mention a CVE ID that affects a product developed by Openzfs — matched by CVE ID, not by vendor name.