{"id":"DEBIAN-CVE-2023-49298","details":"OpenZFS through 2.1.13 and 2.2.x through 2.2.1, in certain scenarios involving applications that try to rely on efficient copying of file data, can replace file contents with zero-valued bytes and thus potentially disable security mechanisms. NOTE: this issue is not always security related, but can be security related in realistic situations. A possible example is cp, from a recent GNU Core Utilities (coreutils) version, when attempting to preserve a rule set for denying unauthorized access. (One might use cp when configuring access control, such as with the /etc/hosts.deny file specified in the IBM Support reference.) NOTE: this issue occurs less often in version 2.2.1, and in versions before 2.1.4, because of the default configuration in those versions.","modified":"2026-09-15T09:02:46.866951124Z","published":"2023-11-24T19:15:07.587Z","upstream":["CVE-2023-49298"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-49298"}],"affected":[{"package":{"name":"zfs-linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/zfs-linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.11-1+deb12u1"}]}],"versions":["0.6.5.10-1","0.6.5.11-1","0.6.5.11-1~bpo8+1","0.6.5.11-1~bpo9+1","0.6.5.5-1","0.6.5.6-1","0.6.5.6-2","0.6.5.7-1","0.6.5.7-2","0.6.5.7-2~bpo8+1","0.6.5.8-1","0.6.5.8-1~bpo8+1","0.6.5.8-2","0.6.5.8-2~bpo8+1","0.6.5.8-3","0.6.5.9-1","0.6.5.9-2","0.6.5.9-2~bpo8+1","0.6.5.9-3","0.6.5.9-4","0.6.5.9-5","0.6.5.9-5+sparc64","0.6.5.9-5~bpo8+1","0.7.11-1","0.7.11-1~bpo8+1","0.7.11-1~bpo9+1","0.7.11-2","0.7.11-3","0.7.12-1","0.7.12-1~bpo9+1","0.7.12-2","0.7.12-3","0.7.12-4","0.7.12-5","0.7.13-1","0.7.13-1~bpo10+1","0.7.13-1~bpo9+1","0.7.3-1","0.7.3-2","0.7.3-3","0.7.3-3~bpo8+1","0.7.3-3~bpo9+1","0.7.4-1","0.7.4-1~bpo8+1","0.7.4-1~bpo9+1","0.7.5-1","0.7.5-1~bpo9+1","0.7.6-1","0.7.6-1~bpo8+1","0.7.6-1~bpo9+1","0.7.9-0.1","0.7.9-1","0.7.9-2","0.7.9-3","0.7.9-3~bpo8+1","0.7.9-3~bpo9+1","0.8.0-1","0.8.0-2","0.8.0~rc3-1","0.8.0~rc4-1","0.8.1-1","0.8.1-2","0.8.1-3","0.8.1-4","0.8.1-4~bpo10+1","0.8.2-1","0.8.2-2","0.8.2-2~bpo10+1","0.8.2-3","0.8.2-3~bpo10+1","0.8.2-4","0.8.2-5","0.8.3-1","0.8.3-1~bpo10+1","0.8.3-2","0.8.4-1","0.8.4-1~bpo10+1","0.8.4-2","0.8.4-2~bpo10+1","0.8.5-1","0.8.5-2","0.8.5-2~bpo10+1","0.8.5-3","0.8.5-3~bpo10+1","0.8.6-1","0.8.6-1~bpo10+1","2.0.0-1~exp1","2.0.1-1","2.0.1-1~exp1","2.0.1-2","2.0.1-3","2.0.2-1","2.0.2-1~bpo10+1","2.0.3-1","2.0.3-1~bpo10+1","2.0.3-2","2.0.3-3","2.0.3-4","2.0.3-5","2.0.3-6","2.0.3-7","2.0.3-8","2.0.3-8~bpo10+1","2.0.3-9","2.0.3-9~bpo10+1","2.0.6-1","2.0.6-1~bpo10+1","2.0.6-1~bpo11+1","2.0.6-2","2.0.7-1~bpo10+1","2.1.1-1","2.1.1-2","2.1.1-3","2.1.11-1","2.1.11-1~bpo11+1","2.1.2-1","2.1.2-1~bpo11+1","2.1.4-1","2.1.4-1~bpo11+1","2.1.5-1","2.1.5-1~bpo11+1","2.1.6-1","2.1.6-2","2.1.6-3","2.1.6-3~bpo11+1","2.1.7-1","2.1.7-1~bpo11+1","2.1.7-2","2.1.8-1","2.1.9-1","2.1.9-1~bpo11+1","2.1.9-2","2.1.9-3","2.1.9-3~bpo11+1","2.1.9-4"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-49298.json"}},{"package":{"name":"zfs-linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/zfs-linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.14-1"}]}],"versions":["0.6.5.10-1","0.6.5.11-1","0.6.5.11-1~bpo8+1","0.6.5.11-1~bpo9+1","0.6.5.5-1","0.6.5.6-1","0.6.5.6-2","0.6.5.7-1","0.6.5.7-2","0.6.5.7-2~bpo8+1","0.6.5.8-1","0.6.5.8-1~bpo8+1","0.6.5.8-2","0.6.5.8-2~bpo8+1","0.6.5.8-3","0.6.5.9-1","0.6.5.9-2","0.6.5.9-2~bpo8+1","0.6.5.9-3","0.6.5.9-4","0.6.5.9-5","0.6.5.9-5+sparc64","0.6.5.9-5~bpo8+1","0.7.11-1","0.7.11-1~bpo8+1","0.7.11-1~bpo9+1","0.7.11-2","0.7.11-3","0.7.12-1","0.7.12-1~bpo9+1","0.7.12-2","0.7.12-3","0.7.12-4","0.7.12-5","0.7.13-1","0.7.13-1~bpo10+1","0.7.13-1~bpo9+1","0.7.3-1","0.7.3-2","0.7.3-3","0.7.3-3~bpo8+1","0.7.3-3~bpo9+1","0.7.4-1","0.7.4-1~bpo8+1","0.7.4-1~bpo9+1","0.7.5-1","0.7.5-1~bpo9+1","0.7.6-1","0.7.6-1~bpo8+1","0.7.6-1~bpo9+1","0.7.9-0.1","0.7.9-1","0.7.9-2","0.7.9-3","0.7.9-3~bpo8+1","0.7.9-3~bpo9+1","0.8.0-1","0.8.0-2","0.8.0~rc3-1","0.8.0~rc4-1","0.8.1-1","0.8.1-2","0.8.1-3","0.8.1-4","0.8.1-4~bpo10+1","0.8.2-1","0.8.2-2","0.8.2-2~bpo10+1","0.8.2-3","0.8.2-3~bpo10+1","0.8.2-4","0.8.2-5","0.8.3-1","0.8.3-1~bpo10+1","0.8.3-2","0.8.4-1","0.8.4-1~bpo10+1","0.8.4-2","0.8.4-2~bpo10+1","0.8.5-1","0.8.5-2","0.8.5-2~bpo10+1","0.8.5-3","0.8.5-3~bpo10+1","0.8.6-1","0.8.6-1~bpo10+1","2.0.0-1~exp1","2.0.1-1","2.0.1-1~exp1","2.0.1-2","2.0.1-3","2.0.2-1","2.0.2-1~bpo10+1","2.0.3-1","2.0.3-1~bpo10+1","2.0.3-2","2.0.3-3","2.0.3-4","2.0.3-5","2.0.3-6","2.0.3-7","2.0.3-8","2.0.3-8~bpo10+1","2.0.3-9","2.0.3-9~bpo10+1","2.0.6-1","2.0.6-1~bpo10+1","2.0.6-1~bpo11+1","2.0.6-2","2.0.7-1~bpo10+1","2.1.1-1","2.1.1-2","2.1.1-3","2.1.11-1","2.1.11-1~bpo11+1","2.1.12-1","2.1.12-2","2.1.12-2~bpo12+1","2.1.13-1","2.1.13-1~bpo11+1","2.1.13-1~bpo12+1","2.1.13-2","2.1.13-2~bpo11+1","2.1.13-2~bpo12+1","2.1.14-1~bpo11+1","2.1.14-1~bpo12+1","2.1.2-1","2.1.2-1~bpo11+1","2.1.4-1","2.1.4-1~bpo11+1","2.1.5-1","2.1.5-1~bpo11+1","2.1.6-1","2.1.6-2","2.1.6-3","2.1.6-3~bpo11+1","2.1.7-1","2.1.7-1~bpo11+1","2.1.7-2","2.1.8-1","2.1.9-1","2.1.9-1~bpo11+1","2.1.9-2","2.1.9-3","2.1.9-3~bpo11+1","2.1.9-4"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-49298.json"}},{"package":{"name":"zfs-linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/zfs-linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.14-1"}]}],"versions":["0.6.5.10-1","0.6.5.11-1","0.6.5.11-1~bpo8+1","0.6.5.11-1~bpo9+1","0.6.5.5-1","0.6.5.6-1","0.6.5.6-2","0.6.5.7-1","0.6.5.7-2","0.6.5.7-2~bpo8+1","0.6.5.8-1","0.6.5.8-1~bpo8+1","0.6.5.8-2","0.6.5.8-2~bpo8+1","0.6.5.8-3","0.6.5.9-1","0.6.5.9-2","0.6.5.9-2~bpo8+1","0.6.5.9-3","0.6.5.9-4","0.6.5.9-5","0.6.5.9-5+sparc64","0.6.5.9-5~bpo8+1","0.7.11-1","0.7.11-1~bpo8+1","0.7.11-1~bpo9+1","0.7.11-2","0.7.11-3","0.7.12-1","0.7.12-1~bpo9+1","0.7.12-2","0.7.12-3","0.7.12-4","0.7.12-5","0.7.13-1","0.7.13-1~bpo10+1","0.7.13-1~bpo9+1","0.7.3-1","0.7.3-2","0.7.3-3","0.7.3-3~bpo8+1","0.7.3-3~bpo9+1","0.7.4-1","0.7.4-1~bpo8+1","0.7.4-1~bpo9+1","0.7.5-1","0.7.5-1~bpo9+1","0.7.6-1","0.7.6-1~bpo8+1","0.7.6-1~bpo9+1","0.7.9-0.1","0.7.9-1","0.7.9-2","0.7.9-3","0.7.9-3~bpo8+1","0.7.9-3~bpo9+1","0.8.0-1","0.8.0-2","0.8.0~rc3-1","0.8.0~rc4-1","0.8.1-1","0.8.1-2","0.8.1-3","0.8.1-4","0.8.1-4~bpo10+1","0.8.2-1","0.8.2-2","0.8.2-2~bpo10+1","0.8.2-3","0.8.2-3~bpo10+1","0.8.2-4","0.8.2-5","0.8.3-1","0.8.3-1~bpo10+1","0.8.3-2","0.8.4-1","0.8.4-1~bpo10+1","0.8.4-2","0.8.4-2~bpo10+1","0.8.5-1","0.8.5-2","0.8.5-2~bpo10+1","0.8.5-3","0.8.5-3~bpo10+1","0.8.6-1","0.8.6-1~bpo10+1","2.0.0-1~exp1","2.0.1-1","2.0.1-1~exp1","2.0.1-2","2.0.1-3","2.0.2-1","2.0.2-1~bpo10+1","2.0.3-1","2.0.3-1~bpo10+1","2.0.3-2","2.0.3-3","2.0.3-4","2.0.3-5","2.0.3-6","2.0.3-7","2.0.3-8","2.0.3-8~bpo10+1","2.0.3-9","2.0.3-9~bpo10+1","2.0.6-1","2.0.6-1~bpo10+1","2.0.6-1~bpo11+1","2.0.6-2","2.0.7-1~bpo10+1","2.1.1-1","2.1.1-2","2.1.1-3","2.1.11-1","2.1.11-1~bpo11+1","2.1.12-1","2.1.12-2","2.1.12-2~bpo12+1","2.1.13-1","2.1.13-1~bpo11+1","2.1.13-1~bpo12+1","2.1.13-2","2.1.13-2~bpo11+1","2.1.13-2~bpo12+1","2.1.14-1~bpo11+1","2.1.14-1~bpo12+1","2.1.2-1","2.1.2-1~bpo11+1","2.1.4-1","2.1.4-1~bpo11+1","2.1.5-1","2.1.5-1~bpo11+1","2.1.6-1","2.1.6-2","2.1.6-3","2.1.6-3~bpo11+1","2.1.7-1","2.1.7-1~bpo11+1","2.1.7-2","2.1.8-1","2.1.9-1","2.1.9-1~bpo11+1","2.1.9-2","2.1.9-3","2.1.9-3~bpo11+1","2.1.9-4"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-49298.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}