Impact
A flaw in the Linux kernel's isofs module leaves a buffer_head reference unreleased when reading a zisofs compressed block pointer table, causing a kernel memory leak. The retained reference prevents the kernel from freeing the associated page cache, which can lead to gradual exhaustion of memory resources and degrade system performance. The issue is a classic resource exhaustion problem, not an arbitrary code execution vector.
Affected Systems
The vulnerability affects the Linux kernel across all distributions that compile the isofs module. No specific kernel version range is provided in the advisory, so any kernel using the isofs implementation is potentially impacted until the indicated patch is applied.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low likelihood of widespread exploitation. The attack requires local access to read or mount a zisofs-compressed ISO image, so an attacker who can influence such file handling on a target system may manifest the resource exhaustion. Due to the low EPSS and lack of known exploitation, the overall risk remains moderate, primarily causing denial of service through memory pressure.
OpenCVE Enrichment
Debian DLA
Debian DSA