Improper input validation in Linux kernel - CVE-2026-46124
Published: May 29, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper input validation in isofs_export_iget when processing block numbers from NFS file handles. A remote user can send a crafted NFS file handle to disclose sensitive information.
Exploitation requires an authenticated NFS peer and affects isofs exported over NFS from loop-mounted images.
How to mitigate CVE-2026-46124
Sources
- https://git.kernel.org/stable/c/0a1af74ae2177bda3aee0837a0546309aa539d0d
- https://git.kernel.org/stable/c/24376458138387fb251e782e624c7776e9826796
- https://git.kernel.org/stable/c/4c721a1d9b3c4fcaf59cc9b2281e3ec5a043e1a6
- https://git.kernel.org/stable/c/afbafeddf23db13fe2edb2d5c0bf4bbb13d7881b
- https://git.kernel.org/stable/c/bb0988ed4f2e26d59bbb58f644cb3a55b7521e21