Description
In the Linux kernel, the following vulnerability has been resolved:

isofs: release zisofs block pointer buffer head

zisofs_fill_pages() reads the compressed block pointer table. The error
paths release the current buffer_head, the loop also releases the old
buffer_head when it advances. However, the success path leaves the last
buffer_head referenced. Release it before returning success.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory exhaustion, potential denial of service
Action: Update Kernel
AI Analysis

Impact

A flaw in the Linux kernel's isofs module leaves a buffer_head reference unreleased when reading a zisofs compressed block pointer table, causing a kernel memory leak. The retained reference prevents the kernel from freeing the associated page cache, which can lead to gradual exhaustion of memory resources and degrade system performance. The issue is a classic resource exhaustion problem, not an arbitrary code execution vector.

Affected Systems

The vulnerability affects the Linux kernel across all distributions that compile the isofs module. No specific kernel version range is provided in the advisory, so any kernel using the isofs implementation is potentially impacted until the indicated patch is applied.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low likelihood of widespread exploitation. The attack requires local access to read or mount a zisofs-compressed ISO image, so an attacker who can influence such file handling on a target system may manifest the resource exhaustion. Due to the low EPSS and lack of known exploitation, the overall risk remains moderate, primarily causing denial of service through memory pressure.

Generated by OpenCVE AI on September 19, 2026 at 13:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that incorporates the fix for the zisofs buffer_head release issue.
  • Avoid mounting or accessing zisofs compressed ISO files until the kernel has been updated, to prevent potential memory exhaustion attacks.
  • After the update, monitor kernel memory usage and I/O behavior for signs of abnormal consumption or slow performance related to zisofs processing.

Generated by OpenCVE AI on September 19, 2026 at 13:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-775

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: isofs: release zisofs block pointer buffer head zisofs_fill_pages() reads the compressed block pointer table. The error paths release the current buffer_head, the loop also releases the old buffer_head when it advances. However, the success path leaves the last buffer_head referenced. Release it before returning success.
Title isofs: release zisofs block pointer buffer head
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:53.716Z

Reserved: 2026-09-11T19:38:34.815Z

Link: CVE-2026-90434

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:48.597

Modified: 2026-09-17T17:17:48.597

Link: CVE-2026-90434

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:45:15Z

Weaknesses
  • CWE-775

    Missing Release of File Descriptor or Handle after Effective Lifetime