CVE-2026-46303
published 2026-06-08CVE-2026-46303: In the Linux kernel, the following vulnerability has been resolved: isofs: validate Rock Ridge CE continuation extent against volume size rock_continue() reads…
PriorityP344high8.2CVSS 3.1
AVNACLPRNUINSUCHILAN
EPSS
0.28%
20.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
isofs: validate Rock Ridge CE continuation extent against volume size
rock_continue() reads rs->cont_extent verbatim from the Rock Ridge CE
record and passes it to sb_bread() without checking that the block
number is within the mounted ISO 9660 volume. commit e595447e177b
("[PATCH] rock.c: handle corrupted directories") added cont_offset
and cont_size rejection for the CE continuation but did not validate
the extent block number itself. commit f54e18f1b831 ("isofs: Fix
infinite looping over CE entries") later capped the CE chain length
at RR_MAX_CE_ENTRIES = 32 but again left the block number unchecked.
With a crafted ISO mounted via udisks2 (desktop optical auto-mount)
or via CAP_SYS_ADMIN mount, rs->cont_extent can therefore point at
an out-of-range block or at blocks belonging to an adjacent
filesystem on the same block device. sb_bread() on an out-of-range
block returns NULL cleanly via the block layer EIO path, so there
is no memory-safety violation. For in-range reads of adjacent-
filesystem data, the CE buffer is parsed as Rock Ridge records and
only the text of SL sub-records reaches userspace through
readlink(), which makes the info-leak channel narrow and difficult
to exploit; still, rejecting the malformed CE outright matches the
rejection shape already present in the same function for
cont_offset and cont_size.
Add an ISOFS_SB(sb)->s_nzones bounds check to rock_continue() next
to the existing offset/size rejection, printing the same
corrupted-directory-entry notice.
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 2.6.32.66 < 2.6.33 | 2.6.33 |
| linux | linux | >= 3.10.64 < 3.11 | 3.11 |
| linux | linux | >= 3.12.36 < 3.13 | 3.13 |
| linux | linux | >= 3.14.28 < 3.15 | 3.15 |
| linux | linux | >= 3.17.8 < 3.18 | 3.18 |
| linux | linux | >= 3.18.2 < 3.19 | 3.19 |
| linux | linux | >= 3.2.67 < 3.3 | 3.3 |
| linux | linux | >= 3.4.107 < 3.5 | 3.5 |
| linux | linux | >= f54e18f1b831c92f6512d2eedb224cd63d607d3d < 8356fb821016797f5677cbeee5ddc0d32a95b4be | 8356fb821016797f5677cbeee5ddc0d32a95b4be |
| linux | linux | >= f54e18f1b831c92f6512d2eedb224cd63d607d3d < d582e12378bc1637f337622feef762f53c43fd57 | d582e12378bc1637f337622feef762f53c43fd57 |
| linux | linux | >= f54e18f1b831c92f6512d2eedb224cd63d607d3d < bf1bc673c587f5ef7e9c09b94aea7c5a7847d4d9 | bf1bc673c587f5ef7e9c09b94aea7c5a7847d4d9 |
| linux | linux | >= f54e18f1b831c92f6512d2eedb224cd63d607d3d < c9b37c8b73f6368e4750e5ccb0632c380b43c6e5 | c9b37c8b73f6368e4750e5ccb0632c380b43c6e5 |
| linux | linux | >= f54e18f1b831c92f6512d2eedb224cd63d607d3d < 22b36fa081f38ab397c7697f9d539211b51a0cfc | 22b36fa081f38ab397c7697f9d539211b51a0cfc |
| linux | linux | >= f54e18f1b831c92f6512d2eedb224cd63d607d3d < e69da8eeab74b4f4505024c38a17bce060fe7df8 | e69da8eeab74b4f4505024c38a17bce060fe7df8 |
| linux | linux | >= f54e18f1b831c92f6512d2eedb224cd63d607d3d < ef048470c90bc8c1b8318bb2ce329da9ef64b9fe | ef048470c90bc8c1b8318bb2ce329da9ef64b9fe |
| linux | linux | >= f54e18f1b831c92f6512d2eedb224cd63d607d3d < a36d990f591320e9dd379ab30063ebfe91d47e1f | a36d990f591320e9dd379ab30063ebfe91d47e1f |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
vendor_redhat8.2HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In the Linux kernel, the following vulnerability has been resolved: isofs: validate Rock Ridge CE continuation extent against volume size rock_continue() reads rs->cont_extent verbatim from the Rock
ghsa_unreviewed·2026-06-08
CVE-2026-46303 In the Linux kernel, the following vulnerability has been resolved: isofs: validate Rock Ridge CE continuation extent against volume size rock_continue() reads rs->cont_extent verbatim from the Rock
In the Linux kernel, the following vulnerability has been resolved:
isofs: validate Rock Ridge CE continuation extent against volume size
rock_continue() reads rs->cont_extent verbatim from the Rock Ridge CE
record and passes it to sb_bread() without checking that the block
number is within the mounted ISO 9660 volume. commit e595447e177b
("[PATCH] rock.c: handle corrupted directories") added cont_offset
and cont_size rejection for the CE continuation but did not validate
the extent block number itself. commit f54e18f1b831 ("isofs: Fix
infinite looping over CE entries") later capped the CE chain length
at RR_MAX_CE_ENTRIES = 32 but again left the block number unchecked.
With a crafted ISO mounted via udisks2 (desktop optical auto-mount)
or via CAP_SYS_ADMIN mount, rs->cont_extent can th
VulDB
Linux Kernel up to 7.1-rc1 isofs rock.c rock_continue cont_extent infinite loop
vuldb·2026-06-08
CVE-2026-46303 [CRITICAL] Linux Kernel up to 7.1-rc1 isofs rock.c rock_continue cont_extent infinite loop
A vulnerability was found in Linux Kernel up to 7.1-rc1. It has been rated as critical. The affected element is the function rock_continue of the file rock.c of the component isofs. Performing a manipulation of the argument cont_extent results in infinite loop.
This vulnerability was named CVE-2026-46303. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is advised.
Ubuntu
Linux kernel (OEM) vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 7.0
CVE-2026-46108 [HIGH] Linux kernel (OEM) vulnerabilities
Title: Linux kernel (OEM) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- PSP security protocol;
- ARM64 architecture;
- PowerPC architecture;
- RISC-V architecture;
- S390 architecture;
- User-Mode Linux (UML);
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- Intel NPU Driver;
- DRBD D
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 2.0
CVE-2026-46073 [LOW] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)
It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TC
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 2.0
CVE-2026-46073 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)
It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A local attacke
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 7.0
CVE-2026-46113 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- PSP security protocol;
- ARM64 architecture;
- PowerPC architecture;
- RISC-V architecture;
- S390 architecture;
- User-Mode Linux (UML);
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- Intel NPU Driver;
- DRBD Distrib
Red Hat
kernel: isofs: validate Rock Ridge CE continuation extent against volume size
vendor_redhat·2026-06-08·CVSS 8.2
CVE-2026-46303 [HIGH] CWE-125 kernel: isofs: validate Rock Ridge CE continuation extent against volume size
kernel: isofs: validate Rock Ridge CE continuation extent against volume size
In the Linux kernel, the following vulnerability has been resolved:
isofs: validate Rock Ridge CE continuation extent against volume size
rock_continue() reads rs->cont_extent verbatim from the Rock Ridge CE
record and passes it to sb_bread() without checking that the block
number is within the mounted ISO 9660 volume. commit e595447e177b
("[PATCH] rock.c: handle corrupted directories") added cont_offset
and cont_size rejection for the CE continuation but did not validate
the extent block number itself. commit f54e18f1b831 ("isofs: Fix
infinite looping over CE entries") later capped the CE chain length
at RR_MAX_CE_ENTRIES = 32 but again left the block number unchecked.
With a crafted ISO mounted via udisks2 (de
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/22b36fa081f38ab397c7697f9d539211b51a0cfchttps://git.kernel.org/stable/c/8356fb821016797f5677cbeee5ddc0d32a95b4behttps://git.kernel.org/stable/c/a36d990f591320e9dd379ab30063ebfe91d47e1fhttps://git.kernel.org/stable/c/bf1bc673c587f5ef7e9c09b94aea7c5a7847d4d9https://git.kernel.org/stable/c/c9b37c8b73f6368e4750e5ccb0632c380b43c6e5https://git.kernel.org/stable/c/d582e12378bc1637f337622feef762f53c43fd57https://git.kernel.org/stable/c/e69da8eeab74b4f4505024c38a17bce060fe7df8https://git.kernel.org/stable/c/ef048470c90bc8c1b8318bb2ce329da9ef64b9fe
2026-06-08
Published