{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  isofs: fix out-of-bounds page array access on empty zisofs block  zisofs_uncompress_block()'s empty-block fast path returns pcount \u003c\u003c PAGE_SHIFT, ignoring the incoming poffset, unlike the decompression path which returns bytes produced relative to poffset. zisofs_fill_pages() uses that return to advance its page cursor, so when the zisofs block size is below PAGE_SIZE and a sub-page block leaves poffset partway into a page, a following empty block over-counts and advances pages[] one element past its end, after which \"if (poffset \u0026\u0026 *pages)\" reads pages[1] out of bounds.  rock.c only rejects a block-size shift \u003e 17, so a crafted \"ZF\" Rock Ridge record can set it below PAGE_SHIFT; the bug is reached by an ordinary read() of a compressed file on such a mounted ISO9660 image.  Return the byte count relative to poffset and zero only [poffset, PAGE_SIZE) of the first page, matching the decompression path. The page-aligned case (poffset == 0) is unaffected.    BUG: KASAN: slab-out-of-bounds in zisofs_read_folio (fs/isofs/compress.c:290)   Read of size 8 at addr ffff88800f5eac48 by task exploit/142    zisofs_read_folio (fs/isofs/compress.c:290)    read_pages (mm/readahead.c:184)    ...    filemap_read (mm/filemap.c:2814)    vfs_read (fs/read_write.c:574)    __x64_sys_pread64 (fs/read_write.c:769)    do_syscall_64 (arch/x86/entry/syscall_64.c:94)    entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)   The buggy address is located 0 bytes to the right of the   allocated 8-byte region in the kmalloc-8 cache",
  "id": "DEBIAN-CVE-2026-89778",
  "modified": "2026-09-17T04:47:33.497173862Z",
  "published": "2026-09-16T09:17:08.253Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-89778"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-89778"
  ]
}