PT-2026-93384 · Linux · Linux Kernel

CVE-2026-89778

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An out-of-bounds page array access exists in the zisofs component of the ISO9660 file system. The issue occurs in the zisofs uncompress block() function's empty-block fast path, which fails to account for the poffset variable when returning the byte count. Consequently, zisofs fill pages() may advance the page cursor beyond the end of the pages[] array. This can be triggered by an ordinary read operation of a compressed file on a mounted ISO9660 image containing a crafted "ZF" Rock Ridge record that sets the block-size shift below PAGE SHIFT. The flaw leads to a slab-out-of-bounds read in the zisofs read folio() function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101652
CVE-2026-89778
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel