---
id: CVE-2026-46303
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  isofs: validate Rock Ridge CE continuation extent against volume size

  rock_continue() reads rs->cont_extent verbatim from the Rock Ridge CE
  record and passes it to sb_…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  isofs: validate Rock Ridge CE continuation extent against volume size

  rock_continue() reads rs->cont_extent verbatim from the Rock Ridge CE
  record and passes it to sb_…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-401
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 2.6.32.66, < 2.6.33'
  - 'linux_kernel >= 3.2.67, < 3.3'
  - 'linux_kernel >= 3.4.107, < 3.5'
  - 'linux_kernel >= 3.10.64, < 3.11'
  - 'linux_kernel >= 3.12.36, < 3.13'
  - 'linux_kernel >= 3.14.28, < 3.15'
  - 'linux_kernel >= 3.17.8, < 3.18'
  - 'linux_kernel >= 3.18.2, < 5.10.258'
  - 'linux_kernel >= 5.11, < 5.15.209'
  - 'linux_kernel >= 5.16, < 6.1.175'
  - 'linux_kernel >= 6.2, < 6.6.140'
  - 'linux_kernel >= 6.7, < 6.12.88'
  - 'linux_kernel >= 6.13, < 6.18.30'
  - 'linux_kernel >= 6.19, < 7.0.7'
  - linux_kernel = 7.1
patched:
  - linux_kernel 7.0.7
published: '2026-06-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T09:18:09.583'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-46303'
references:
  - url: 'https://git.kernel.org/stable/c/22b36fa081f38ab397c7697f9d539211b51a0cfc'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8356fb821016797f5677cbeee5ddc0d32a95b4be'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a36d990f591320e9dd379ab30063ebfe91d47e1f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/bf1bc673c587f5ef7e9c09b94aea7c5a7847d4d9'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c9b37c8b73f6368e4750e5ccb0632c380b43c6e5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d582e12378bc1637f337622feef762f53c43fd57'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e69da8eeab74b4f4505024c38a17bce060fe7df8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ef048470c90bc8c1b8318bb2ce329da9ef64b9fe'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-019113.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
tags:
  - nvd
  - cve.org
epss: 0.00312
epssPercentile: 0.24285
ingestedAt: '2026-07-07T18:42:24.328Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

isofs: validate Rock Ridge CE continuation extent against volume size

rock_continue() reads rs->cont_extent verbatim from the Rock Ridge CE
record and passes it to sb_bread() without checking that the block
number is within the mounted ISO 9660 volume.  commit e595447e177b
("[PATCH] rock.c: handle corrupted directories") added cont_offset
and cont_size rejection for the CE continuation but did not validate
the extent block number itself.  commit f54e18f1b831 ("isofs: Fix
infinite looping over CE entries") later capped the CE chain length
at RR_MAX_CE_ENTRIES = 32 but again left the block number unchecked.

With a crafted ISO mounted via udisks2 (desktop optical auto-mount)
or via CAP_SYS_ADMIN mount, rs->cont_extent can therefore point at
an out-of-range block or at blocks belonging to an adjacent
filesystem on the same block device.  sb_bread() on an out-of-range
block returns NULL cleanly via the block layer EIO path, so there
is no memory-safety violation.  For in-range reads of adjacent-
filesystem data, the CE buffer is parsed as Rock Ridge records and
only the text of SL sub-records reaches userspace through
readlink(), which makes the info-leak channel narrow and difficult
to exploit; still, rejecting the malformed CE outright matches the
rejection shape already present in the same function for
cont_offset and cont_size.

Add an ISOFS_SB(sb)->s_nzones bounds check to rock_continue() next
to the existing offset/size rejection, printing the same
corrupted-directory-entry notice.

## Affected

- `linux_kernel >= 2.6.32.66, < 2.6.33`
- `linux_kernel >= 3.2.67, < 3.3`
- `linux_kernel >= 3.4.107, < 3.5`
- `linux_kernel >= 3.10.64, < 3.11`
- `linux_kernel >= 3.12.36, < 3.13`
- `linux_kernel >= 3.14.28, < 3.15`
- `linux_kernel >= 3.17.8, < 3.18`
- `linux_kernel >= 3.18.2, < 5.10.258`
- `linux_kernel >= 5.11, < 5.15.209`
- `linux_kernel >= 5.16, < 6.1.175`
- `linux_kernel >= 6.2, < 6.6.140`
- `linux_kernel >= 6.7, < 6.12.88`
- `linux_kernel >= 6.13, < 6.18.30`
- `linux_kernel >= 6.19, < 7.0.7`
- `linux_kernel = 7.1`

## Remediation

Upgrade past the affected range:

- `linux_kernel 7.0.7`
