CVE-2026-46303: isofs: validate Rock Ridge CE continuation extent against volume size
In the Linux kernel, the following vulnerability has been resolved:
isofs: validate Rock Ridge CE continuation extent against volume size
rockcontinue() reads rs->contextent verbatim from the Rock Ridge CE record and passes it to sbbread() without checking that the block number is within the mounted ISO 9660 volume. commit e595447e177b ("[PATCH] rock.c: handle corrupted directories") added contoffset and contsize rejection for the CE continuation but did not validate the extent block number itself. commit f54e18f1b831 ("isofs: Fix infinite looping over CE entries") later capped the CE chain length at RRMAXCEENTRIES = 32 but again left the block number unchecked.
With a crafted ISO mounted via udisks2 (desktop optical auto-mount) or via CAPSYSADMIN mount, rs->contextent can therefore point at an out-of-range block or at blocks belonging to an adjacent filesystem on the same block device. sbbread() on an out-of-range block returns NULL cleanly via the block layer EIO path, so there is no memory-safety violation. For in-range reads of adjacent- filesystem data, the CE buffer is parsed as Rock Ridge records and only the text of SL sub-records reaches userspace through readlink(), which makes the info-leak channel narrow and difficult to exploit; still, rejecting the malformed CE outright matches the rejection shape already present in the same function for contoffset and contsize.
Add an ISOFSSB(sb)->snzones bounds check to rockcontinue() next to the existing offset/size rejection, printing the same corrupted-directory-entry notice.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.141.1-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch e595447e177b - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch f54e18f1b831 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch isofs: validate Rock Ridge CE continuation extent against volume size
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46303?
CVE-2026-46303 has a risk score of 15, indicating a critical severity level.
How do I fix CVE-2026-46303?
To fix CVE-2026-46303, ensure that you apply the latest patch provided for the Linux kernel.
What systems are affected by CVE-2026-46303?
CVE-2026-46303 affects systems running the vulnerable versions of the Linux kernel that utilize the ISO filesystem.
What does CVE-2026-46303 involve?
CVE-2026-46303 involves improper validation of the Rock Ridge CE continuation extent against the volume size, leading to potential vulnerabilities.
When was CVE-2026-46303 published?
CVE-2026-46303 was published on June 8, 2026.