KernelScan.io

CRITICAL Introduced in 2.6.33

isofs ZisofsBlock OOB

CVE-2026-89778

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI6.3MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: isofs: fix out-of-bounds page array access on empty zisofs block zisofs_uncompress_block()'s empty-block fast path returns pcount << PAGE_SHIFT, ignoring the incoming poffset, unlike the decompression path which returns bytes produced relative to poffset. zisofs_fill_pages() uses that return to advance its page cursor, so when the zisofs block size is below PAGE_SIZE and a sub-page block leaves poffset partway into a page, a following empty block over-counts and advances pages[] one element past its end, after which "if (poffset && *pages)" reads pages[1] out of bounds. rock.c only rejects a block-size shift > 17, so a crafted "ZF" Rock Ridge record can set it below PAGE_SHIFT; the bug is reached by an ordinary read() of a compressed file on such a mounted ISO9660 image. Return the byte count relative to poffset and zero only [poffset, PAGE_SIZE) of the first page, matching the decompression path. The page-aligned case (poffset == 0) is unaffected. BUG: KASAN: slab-out-of-bounds in zisofs_read_folio (fs/isofs/compress.c:290) Read of size 8 at addr ffff88800f5eac48 by task exploit/142 zisofs_read_folio (fs/isofs/compress.c:290) read_pages (mm/readahead.c:184) ... filemap_read (mm/filemap.c:2814) vfs_read (fs/read_write.c:574) __x64_sys_pread64 (fs/read_write.c:769) do_syscall_64 (arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) The buggy address is located 0 bytes to the right of the allocated 8-byte region in the kmalloc-8 cache

02

Engine v0.6.0

Risk summary

A crafted ISO9660 image with a malicious Rock Ridge compression record can trigger an out-of-bounds page-array read in the kernel's zisofs decompression code when any compressed file on that image is read. The image must first be mounted, which requires root privileges (CAP_SYS_ADMIN) or physical access to insert removable media that is automounted. The primary impact is a potential kernel crash, with possible limited memory corruption if the out-of-bounds pointer value is dereferenced as a page address.

Affectedfs/isofs/compress.c (isofs/zisofs)

Vulnerability analysis

When reading a compressed file on a mounted ISO9660 image whose metadata sets the compression block size smaller than the kernel page size, an empty compression block causes the kernel's internal page list to advance past its end. The next check then reads a page address from outside the allocated memory. If that stray value is non-zero, the kernel may treat it as a valid page and try to write to it, causing a crash or memory corruption. The fix makes the empty-block handling count bytes relative to the current position inside the page, matching how the normal decompression path works, so the page list no longer over-advances. The bug is reached by an ordinary read of a compressed file on a mounted crafted ISO9660 image; mounting the image requires root-level privileges, or the image can be introduced via physically accessible removable media that the system automounts.

03

BranchIntroducedFixed inPatch commit
mainline2.6.337.3-rc168d4d3e78150
7.22.6.337.2.69c6eace8d07e
6.12.6.336.1.188ad3249cdf9d4
6.62.6.336.6.15785904076cece
5.152.6.335.15.2218b994ac5778a
6.182.6.336.18.52cd616aa0449a
6.122.6.336.12.110f03425dcbe04