Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2020-24717
Homebrew vulnerability analysis and mitigation

Overview

OpenZFS before version 2.0.0-rc1, when used on FreeBSD, contains a security vulnerability where group permissions are misinterpreted as user permissions. This issue was discovered in August 2020 and affects the permission handling mechanism, specifically demonstrated by mode 0770 being treated as equivalent to mode 0777 (NVD, CVE).

Technical details

The vulnerability stems from incorrect UNIX permissions checking in the FreeBSD implementation of OpenZFS. The issue specifically affects how the system interprets group permissions, treating them as user permissions. This results in a privilege escalation where files with mode 0770 (rwxrwx---) are effectively treated as mode 0777 (rwxrwxrwx), granting execute permissions to all users regardless of intended restrictions. The vulnerability has been assigned a CVSS v3.1 Base Score of 7.8 (HIGH) with vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (NVD).

Impact

The vulnerability can lead to privilege escalation as files intended to be restricted become accessible to unauthorized users. This particularly affects system security when group-only executable files become executable by all users, potentially exposing sensitive system resources or functionality to unauthorized access (NVD).

Exploitability

The vulnerability requires local access to the system and can be exploited by setting specific file permissions. The exploit can be demonstrated by creating a file with mode 0770, which should restrict access to owner and group members, but instead becomes accessible to all users as if it had mode 0777 permissions (NVD).

Mitigation and workarounds

The vulnerability was fixed in OpenZFS version 2.0.0-rc1. The fix involves correcting the UNIX permissions checking mechanism in the FreeBSD implementation. Users are advised to upgrade to OpenZFS version 2.0.0-rc1 or later to address this security issue (GitHub Patch).

Additional resources


SourceThis report was generated using AI

Related Homebrew vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91782LOW1.9
  • NixOS logoNixOS
  • gcc10-binutils
NoYesSep 15, 2026
CVE-2026-91781LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91780LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91779LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-90831LOW1.9
  • NixOS logoNixOS
  • gcc-toolset-16-binutils.src
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management