9.8

CVE-2026-89778

isofs: fix out-of-bounds page array access on empty zisofs block

In the Linux kernel, the following vulnerability has been resolved:

isofs: fix out-of-bounds page array access on empty zisofs block

zisofs_uncompress_block()'s empty-block fast path returns
pcount << PAGE_SHIFT, ignoring the incoming poffset, unlike the
decompression path which returns bytes produced relative to poffset.
zisofs_fill_pages() uses that return to advance its page cursor, so when
the zisofs block size is below PAGE_SIZE and a sub-page block leaves
poffset partway into a page, a following empty block over-counts and
advances pages[] one element past its end, after which
"if (poffset && *pages)" reads pages[1] out of bounds.  rock.c only
rejects a block-size shift > 17, so a crafted "ZF" Rock Ridge record can
set it below PAGE_SHIFT; the bug is reached by an ordinary read() of a
compressed file on such a mounted ISO9660 image.

Return the byte count relative to poffset and zero only
[poffset, PAGE_SIZE) of the first page, matching the decompression path.
The page-aligned case (poffset == 0) is unaffected.

  BUG: KASAN: slab-out-of-bounds in zisofs_read_folio (fs/isofs/compress.c:290)
  Read of size 8 at addr ffff88800f5eac48 by task exploit/142
   zisofs_read_folio (fs/isofs/compress.c:290)
   read_pages (mm/readahead.c:184)
   ...
   filemap_read (mm/filemap.c:2814)
   vfs_read (fs/read_write.c:574)
   __x64_sys_pread64 (fs/read_write.c:769)
   do_syscall_64 (arch/x86/entry/syscall_64.c:94)
   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
  The buggy address is located 0 bytes to the right of the
  allocated 8-byte region in the kmalloc-8 cache
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 59bc055211b8d266ab6089158058bf8268e02006
Version < 8b994ac5778a725982fd6a8a3afcaa068d4a93e3
Status affected
Version 59bc055211b8d266ab6089158058bf8268e02006
Version < ad3249cdf9d4ba34bb8b1ff3956a4020fdfb5b0a
Status affected
Version 59bc055211b8d266ab6089158058bf8268e02006
Version < 85904076cece72ee3194646ad7ac8e6659d999aa
Status affected
Version 59bc055211b8d266ab6089158058bf8268e02006
Version < f03425dcbe04aec3c27b9917e97d7d23a2908dda
Status affected
Version 59bc055211b8d266ab6089158058bf8268e02006
Version < cd616aa0449a772a6956abf03358f0ff31720580
Status affected
Version 59bc055211b8d266ab6089158058bf8268e02006
Version < 9c6eace8d07e90f038c89eb3b756d65a7e259d48
Status affected
Version 59bc055211b8d266ab6089158058bf8268e02006
Version < 68d4d3e78150c7ed7d1195af63ad1e6ace30c661
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.33
Status affected
Version 0
Version < 2.6.33
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.108
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/8b994ac5778a725982fd6a8a3afcaa068d4a93e3
https://git.kernel.org/stable/c/ad3249cdf9d4ba34bb8b1ff3956a4020fdfb5b0a
https://git.kernel.org/stable/c/85904076cece72ee3194646ad7ac8e6659d999aa
https://git.kernel.org/stable/c/f03425dcbe04aec3c27b9917e97d7d23a2908dda
https://git.kernel.org/stable/c/cd616aa0449a772a6956abf03358f0ff31720580
https://git.kernel.org/stable/c/9c6eace8d07e90f038c89eb3b756d65a7e259d48
https://git.kernel.org/stable/c/68d4d3e78150c7ed7d1195af63ad1e6ace30c661