Executive brief
A vulnerability in the Linux kernel's ISO file system (isofs) could allow an authorized network user to view unintended data when a disk image is shared over a network. By sending a specially crafted request, an attacker can trick the server into reading raw data from the storage device and returning it as file metadata. This could lead to the exposure of small amounts of data from other parts of the same storage device.
Technical details
A vulnerability in isofs_export_iget() exists where block numbers provided via NFS file handles (ifid->block or ifid->parent_block) are not sufficiently validated against the filesystem boundaries. While the code previously rejected block 0, it failed to check if the block number exceeded the total number of zones (s_nzones). An authenticated NFS client can provide a crafted file handle to trigger sb_bread() on any in-range block of the underlying block device. While out-of-range reads fail safely, in-range reads of adjacent partitions or unrelated data on the same device can result in that data being leaked to the client as dentry metadata. The fix adds a boundary check against ISOFS_SB(sb)->s_nzones.
Affected products
- Linux Linux kernel All versions prior to the May 2026 patches
Timeline
- 2026-04-19: other: Patch submitted by researcher Michael Bommarito
- 2026-05-28: advisory: CVE-2026-46124 published
References
- https://git.kernel.org/stable/c/0a1af74ae2177bda3aee0837a0546309aa539d0d
- https://git.kernel.org/stable/c/24376458138387fb251e782e624c7776e9826796
- https://git.kernel.org/stable/c/4c721a1d9b3c4fcaf59cc9b2281e3ec5a043e1a6
- https://git.kernel.org/stable/c/afbafeddf23db13fe2edb2d5c0bf4bbb13d7881b
- https://git.kernel.org/stable/c/bb0988ed4f2e26d59bbb58f644cb3a55b7521e21