PT-2026-93384 · Linux · Linux Kernel
CVE-2026-89778
·
Published
2026-09-16
·
Updated
2026-09-24
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An out-of-bounds page array access exists in the zisofs component of the ISO9660 file system. The issue occurs in the
zisofs uncompress block() function's empty-block fast path, which fails to account for the poffset variable when returning the byte count. Consequently, zisofs fill pages() may advance the page cursor beyond the end of the pages[] array. This can be triggered by an ordinary read operation of a compressed file on a mounted ISO9660 image containing a crafted "ZF" Rock Ridge record that sets the block-size shift below PAGE SHIFT. The flaw leads to a slab-out-of-bounds read in the zisofs read folio() function.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel