External risk intelligence

Linux Kernel ISOFS Out-of-Bounds Read

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-89778

This vulnerability requires a user to mount a maliciously crafted ISO9660 filesystem image. Exploitation is restricted to local system operations, as it involves kernel-level handling of specific decompression routines triggered by reading files from a mounted medium. It is not remotely exploitable via network services or standard internet-facing attack vectors.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the Linux kernel's handling of ISO9660 filesystems could allow for an out-of-bounds memory access when reading specially crafted compressed files. This issue has been resolved in the Linux kernel.

  • Out-of-bounds memory access in file reading.
  • Affects systems mounting crafted ISO9660 images.
  • Confirm relevance and exposure for affected systems.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by tricking a user or system into mounting a specially crafted ISO9660 image. When a user or process then attempts to read a compressed file from this image, the kernel's handling of empty blocks in the zisofs compression format can be manipulated. This manipulation leads to an out-of-bounds read within the kernel's memory.

  • Requires mounting a crafted ISO image.
  • Triggered by reading a compressed file.
  • Leads to kernel memory corruption.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could affect system stability and potentially lead to unauthorized data access. When a specially crafted ISO9660 image with a specific zisofs configuration is mounted and a compressed file is read, the kernel may attempt to read memory beyond allocated bounds.

  • Kernel memory could be exposed.
  • Reading a specially crafted file may trigger it.
  • System instability or data corruption may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability resides in the Linux kernel's `isofs` module, specifically affecting the handling of compressed files within ISO9660 images. The primary impact is an out-of-bounds read due to incorrect calculation of page array access when dealing with specific empty block conditions in zisofs compressed data. Infrastructure or platform teams responsible for managing the Linux kernel and its components are likely to own this issue. The first practical step is to identify all systems where the kernel is deployed, determine if they are exposed to potentially malicious ISO images, and then plan for kernel updates.

  • Kernel and infrastructure teams own the fix.
  • Verify if kernel is exposed to crafted ISO images.
  • Plan for kernel updates or package rollbacks.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Linux kernel's isofs component used for?

The isofs component is the part of the Linux kernel responsible for reading and managing ISO9660 filesystems. These filesystems are the standard format for optical media, such as CDs and DVDs, and are often used for distribution files or disk images.

What is the weakness in CVE-2026-89778?

This vulnerability is an out-of-bounds memory access issue. It happens because the kernel's decompression logic for zisofs files incorrectly calculates how much data is being read from specific compressed blocks, causing the system to attempt to access memory locations outside of authorized limits.

How is this memory access error triggered?

The bug is triggered when a system mounts a specially crafted ISO9660 filesystem and a process reads a compressed file from it. The issue only manifests when the zisofs block size is configured to be smaller than the page size; standard, non-malicious ISO images do not cause this error.

Is my system at risk from internet-based attacks?

According to Halo Surface Signal, this vulnerability is not remotely exploitable via network services. Because it requires a malicious ISO image to be physically or logically mounted by the local system, the risk is effectively restricted to local system operations rather than internet-facing entry points.

What should I do if my system uses the isofs module?

Infrastructure teams should first inventory systems that mount ISO9660 images. Since this is a kernel-level issue, the primary response is to apply the latest security updates provided by your Linux distribution, which contain the corrected decompression logic for zisofs files.

References