In the Linux kernel, the following vulnerability has been resolved:
isofs: bound Rock Ridge symlink components to the SL record
get_symlink_chunk() and the SL handling in parse_rock_ridge_inode_internal() walk the variable-length components of a Rock Ridge "SL" (symbolic link) record. Each component is a two-byte header (flags, len) followed by len bytes of text, so it occupies slp->len + 2 bytes. Both loops read slp->len and advance to the next component, and get_symlink_chunk() additionally does memcpy(rpnt, slp->text, slp->len), but neither checks that the component lies within the SL record before dereferencing it.
A crafted SL record whose component declares a len that runs past the record (rr->len) therefore triggers an out-of-bounds read of up to 255 bytes. When the record sits at the tail of its backing buffer - for example a small kmalloc()ed continuation block reached through a CE record - the read crosses the allocation; get_symlink_chunk() then copies the out-of-bounds bytes into the symlink body returned to user space by readlink(), disclosing adjacent kernel memory.
ISO 9660 images are routinely mounted from untrusted removable media - desktop environments auto-mount them (e.g. via udisks2) without CAP_SYS_ADMIN - so the record contents are attacker-controlled.
Reject any component that does not fit in the remaining record bytes before using it. In get_symlink_chunk() return NULL, like the existing output-buffer (plimit) checks, so a malformed record makes readlink() fail with -EIO rather than silently returning a truncated target; in parse_rock_ridge_inode_internal() stop the inode-size walk.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade kernel6.12-debuginfoUpgrade perf6.18-debuginfoUpgrade kernel-debuginfoUpgrade kernel6.12-modules-extraUpgrade kernel6.12-toolsUpgrade kernel-headersUpgrade kernel6.12-modules-extra-commonUpgrade kernel-modules-extra-commonUpgrade kernel6.18-debuginfo-common-aarch64Upgrade kernel6.18-debuginfoUpgrade perf6.12Upgrade python3-perf6.18Upgrade kernelUpgrade python3-perf6.18-debuginfoUpgrade kernel-debuginfo-common-x86_64Upgrade bpftool6.18-debuginfoUpgrade kernel6.18-headersUpgrade kernel6.18-tools-debuginfoUpgrade microvm-kernel6.18Upgrade perf-debuginfoUpgrade bpftool6.12Upgrade kernel6.12-debuginfo-common-aarch64Upgrade kernel-livepatch-6.18.39-79.141Upgrade bpftool6.12-debuginfoUpgrade kernel6.12-tools-develUpgrade kernel6.12-debuginfo-common-x86_64Upgrade kernel6.12Upgrade kernel6.12-develUpgrade perf6.12-debuginfoUpgrade python3-perfUpgrade kernel-modules-extraUpgrade bpftool-debuginfoUpgrade kernel6.18-modules-extra-commonUpgrade kernel-debuginfo-common-aarch64Upgrade kernel6.12-tools-debuginfoUpgrade bpftoolUpgrade kernel6.18Upgrade kernel-toolsUpgrade kernel6.18-debuginfo-common-x86_64Upgrade kernel6.18-develUpgrade bpftool6.18Upgrade python3-perf6.12-debuginfoUpgrade kernel-livepatch-6.1.180-225.360Upgrade python3-perf-debuginfoUpgrade kernel-tools-develUpgrade kernel-livepatch-6.12.100-125.179Upgrade kernel-develUpgrade perf6.18Upgrade perfUpgrade kernel-tools-debuginfoUpgrade kernel6.18-toolsUpgrade python3-perf6.12Upgrade kernel6.18-tools-develUpgrade kernel6.12-headersUpgrade kernel6.18-modules-extra | Aug 18, 2026 | Jul 25, 2026 |
| Debian | — | Upgrade linux-6.12Upgrade linux-6.1Upgrade linux | Jul 28, 2026 | Jul 28, 2026 |
| Ubuntu | — | Upgrade linux-image-realtimeUpgrade linux-image-aws-64kUpgrade linux-image-generic-hwe-26.04Upgrade linux-image-raspi-7.0Upgrade linux-image-raspi-realtime-7.0Upgrade linux-image-nvidia-64k-hwe-26.04Upgrade linux-image-nvidia-bos-64kUpgrade linux-image-realtime-64k-7.0Upgrade linux-image-gcp-64k-7.0Upgrade linux-image-aws-7.0Upgrade linux-image-gke-64k-7.0Upgrade linux-image-gcpUpgrade linux-image-7.0.0-2018-nvidia-bosUpgrade linux-image-7.0.0-31-genericUpgrade linux-image-gke-7.0Upgrade linux-image-raspiUpgrade linux-image-realtime-hwe-26.04Upgrade linux-image-7.0.0-1018-nvidia-64kUpgrade linux-image-realtime-64k-hwe-26.04Upgrade linux-image-gcp-64kUpgrade linux-image-nvidia-64kUpgrade linux-image-realtime-64kUpgrade linux-image-oem-7.0Upgrade linux-image-gke-64k-hwe-26.04Upgrade linux-image-7.0.0-1012-awsUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-generic-7.0Upgrade linux-image-awsUpgrade linux-image-oem-26.04aUpgrade linux-image-7.0.0-1006-gke-64kUpgrade linux-image-7.0.0-1012-aws-64kUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-nvidia-bosUpgrade linux-image-generic-64k-7.0Upgrade linux-image-gke-64kUpgrade linux-image-gkeUpgrade linux-image-gke-hwe-26.04Upgrade linux-image-nvidia-hwe-26.04Upgrade linux-image-aws-64k-7.0Upgrade linux-image-7.0.0-1011-gcp-64kUpgrade linux-image-7.0.0-1006-gkeUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-gcp-7.0Upgrade linux-image-7.0.0-1013-ibmUpgrade linux-image-7.0.0-1019-raspiUpgrade linux-image-virtual-hwe-26.04Upgrade linux-image-nvidia-bos-7.0Upgrade linux-image-ibmUpgrade linux-image-7.0.0-1018-nvidiaUpgrade linux-image-ibm-7.0Upgrade linux-image-7.0.0-2018-nvidia-bos-64kUpgrade linux-image-7.0.0-31-realtimeUpgrade linux-image-oem-26.04Upgrade linux-image-virtual-7.0Upgrade linux-image-generic-64k-hwe-26.04Upgrade linux-image-7.0.0-1011-gcpUpgrade linux-image-realtime-7.0Upgrade linux-image-nvidiaUpgrade linux-image-raspi-realtimeUpgrade linux-image-nvidia-64k-7.0Upgrade linux-image-7.0.0-31-realtime-64kUpgrade linux-image-7.0.0-1019-raspi-realtimeUpgrade linux-image-nvidia-bos-64k-7.0Upgrade linux-image-genericUpgrade linux-image-oem-26.04bUpgrade linux-image-generic-64kUpgrade linux-image-nvidia-7.0Upgrade linux-image-7.0.0-31-generic-64kUpgrade linux-image-virtualUpgrade linux-image-7.0.0-1013-oem | Sep 14, 2026 | Sep 7, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 3, 2026 | Jul 25, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub