Out-of-Bounds Access Vulnerability in Linux Kernel Affects ISOs
CVE-2026-89778

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-89778?

A vulnerability in the Linux kernel's zisofs compression module allows for out-of-bounds access due to flawed handling of empty zisofs blocks. Specifically, the zisofs_uncompress_block() function fails to correctly consider the incoming poffset when returning block sizes, which may lead to an invalid read beyond allocated memory. This flaw could be exploited by crafted 'ZF' Rock Ridge records on a mounted ISO9660 image, allowing remote attackers to manipulate memory access during file reads. A patch has been issued to ensure that the byte count aligns correctly with poffset and to enhance overall system security. Users are advised to update their kernel to the fixed version.

Affected Version(s)

Linux 59bc055211b8d266ab6089158058bf8268e02006 < 8b994ac5778a725982fd6a8a3afcaa068d4a93e3

Linux 59bc055211b8d266ab6089158058bf8268e02006

Linux 59bc055211b8d266ab6089158058bf8268e02006 < 85904076cece72ee3194646ad7ac8e6659d999aa

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.