Executive brief
A vulnerability in the Linux kernel's ISO filesystem driver could allow a malicious actor to read small amounts of data from other filesystems on the same physical disk. By providing a specially crafted ISO image (such as on a USB drive or CD), the system might be tricked into reading data outside the boundaries of the disc image when it is automatically or manually mounted. While the amount of data that can be leaked is very limited, it represents a potential privacy risk on shared systems.
Technical details
A vulnerability in the rock_continue() function in fs/isofs/rock.c was identified where the rs->cont_extent value was read from the Rock Ridge CE record and passed to sb_bread() without bounds checking against the volume size (s_nzones). An attacker with the ability to mount a crafted ISO 9660 image (e.g., via udisks2 auto-mount or CAP_SYS_ADMIN) could point the continuation extent to blocks outside the ISO volume. If these blocks belong to an adjacent filesystem on the same block device, the data is parsed as Rock Ridge records. While most data is rejected, text from SL (Symbolic Link) sub-records can be leaked to userspace via the readlink() system call. The fix adds a bounds check against ISOFS_SB(sb)->s_nzones.
Affected products
- Linux Foundation Linux kernel Fixed in various stable branches including 6.x and earlier versions
Timeline
- 2026-04-19: other: Patch authored
- 2026-06-08: advisory: CVE published
References
- https://git.kernel.org/stable/c/22b36fa081f38ab397c7697f9d539211b51a0cfc
- https://git.kernel.org/stable/c/8356fb821016797f5677cbeee5ddc0d32a95b4be
- https://git.kernel.org/stable/c/a36d990f591320e9dd379ab30063ebfe91d47e1f
- https://git.kernel.org/stable/c/bf1bc673c587f5ef7e9c09b94aea7c5a7847d4d9
- https://git.kernel.org/stable/c/c9b37c8b73f6368e4750e5ccb0632c380b43c6e5
- https://git.kernel.org/stable/c/d582e12378bc1637f337622feef762f53c43fd57
- https://git.kernel.org/stable/c/e69da8eeab74b4f4505024c38a17bce060fe7df8