Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-89664.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-89664
Upstream
Published
2026-06-08T17:16:48Z
Modified
2026-08-28T17:48:10.982750707Z
Summary
CVE-2026-46303 affecting package kernel for versions less than 6.6.141.1-1
Details

In the Linux kernel, the following vulnerability has been resolved:

isofs: validate Rock Ridge CE continuation extent against volume size

rockcontinue() reads rs->contextent verbatim from the Rock Ridge CE record and passes it to sbbread() without checking that the block number is within the mounted ISO 9660 volume. commit e595447e177b ("[PATCH] rock.c: handle corrupted directories") added contoffset and contsize rejection for the CE continuation but did not validate the extent block number itself. commit f54e18f1b831 ("isofs: Fix infinite looping over CE entries") later capped the CE chain length at RRMAXCEENTRIES = 32 but again left the block number unchecked.

With a crafted ISO mounted via udisks2 (desktop optical auto-mount) or via CAPSYSADMIN mount, rs->contextent can therefore point at an out-of-range block or at blocks belonging to an adjacent filesystem on the same block device. sbbread() on an out-of-range block returns NULL cleanly via the block layer EIO path, so there is no memory-safety violation. For in-range reads of adjacent- filesystem data, the CE buffer is parsed as Rock Ridge records and only the text of SL sub-records reaches userspace through readlink(), which makes the info-leak channel narrow and difficult to exploit; still, rejecting the malformed CE outright matches the rejection shape already present in the same function for contoffset and contsize.

Add an ISOFSSB(sb)->snzones bounds check to rock_continue() next to the existing offset/size rejection, printing the same corrupted-directory-entry notice.

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.6.141.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-89664.json"