7.1

CVE-2026-90203

Squashfs: check block offset is not negative

In the Linux kernel, the following vulnerability has been resolved:

Squashfs: check block offset is not negative

If a negative offset is read off disk (for example the offset into the
decompressed fragment block), this will cause squashfs_copy_data() to
perform an out of bounds access.

Fix by checking if offset is negative, and returning 0.  This matches
existing behaviour where an offset beyond the block returns 0 bytes
copied.

To trigger this out of bounds access requires a crafted Squashfs
filesystem and CAP_SYS_ADMIN to mount it.  Unprivileged users will not be
able to mount such a filesystem, but once mounted, an unprivileged user
can trigger the out of bounds access by reading the crafted file with the
negative offset.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version f400e12656ab518be107febfe2315fb1eab5a342
Version < b169185d5c672b989985c6c2e38cafab2548ba88
Status affected
Version f400e12656ab518be107febfe2315fb1eab5a342
Version < c2a126fca820ae74872da28de68dc74d4595dc4b
Status affected
Version f400e12656ab518be107febfe2315fb1eab5a342
Version < 95dadf366c117dcdca78a570e6832071deab1ecd
Status affected
Version f400e12656ab518be107febfe2315fb1eab5a342
Version < 3d2f0cb66c909ea2312cdef465165bb9a3ba2d84
Status affected
Version f400e12656ab518be107febfe2315fb1eab5a342
Version < bbb2218eb072b0a15dc063929200183bd23c2344
Status affected
Version f400e12656ab518be107febfe2315fb1eab5a342
Version < d0a3729d464fcf516416a41cf304c0c92126ee03
Status affected
Version f400e12656ab518be107febfe2315fb1eab5a342
Version < e4afd90bc7bf3dd477970c6c42bdd29ad3fda7fe
Status affected
Version f400e12656ab518be107febfe2315fb1eab5a342
Version < e300eb5002925b29be803d2661af07266cfa267e
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.29
Status affected
Version 0
Version < 2.6.29
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.064
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/b169185d5c672b989985c6c2e38cafab2548ba88
https://git.kernel.org/stable/c/c2a126fca820ae74872da28de68dc74d4595dc4b
https://git.kernel.org/stable/c/95dadf366c117dcdca78a570e6832071deab1ecd
https://git.kernel.org/stable/c/3d2f0cb66c909ea2312cdef465165bb9a3ba2d84
https://git.kernel.org/stable/c/bbb2218eb072b0a15dc063929200183bd23c2344
https://git.kernel.org/stable/c/d0a3729d464fcf516416a41cf304c0c92126ee03
https://git.kernel.org/stable/c/e4afd90bc7bf3dd477970c6c42bdd29ad3fda7fe
https://git.kernel.org/stable/c/e300eb5002925b29be803d2661af07266cfa267e