CVE-2026-90203

Summary

In the Linux kernel, the following vulnerability has been resolved:

Squashfs: check block offset is not negative

If a negative offset is read off disk (for example the offset into the decompressed fragment block), this will cause squashfs_copy_data() to perform an out of bounds access.

Fix by checking if offset is negative, and returning 0. This matches existing behaviour where an offset beyond the block returns 0 bytes copied.

To trigger this out of bounds access requires a crafted Squashfs filesystem and CAP_SYS_ADMIN to mount it. Unprivileged users will not be able to mount such a filesystem, but once mounted, an unprivileged user can trigger the out of bounds access by reading the crafted file with the negative offset.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxf400e12656ab518be107febfe2315fb1eab5a342 < b169185d5c672b989985c6c2e38cafab2548ba88affected
LinuxLinuxf400e12656ab518be107febfe2315fb1eab5a342 < c2a126fca820ae74872da28de68dc74d4595dc4baffected
LinuxLinuxf400e12656ab518be107febfe2315fb1eab5a342 < 95dadf366c117dcdca78a570e6832071deab1ecdaffected
LinuxLinuxf400e12656ab518be107febfe2315fb1eab5a342 < 3d2f0cb66c909ea2312cdef465165bb9a3ba2d84affected
LinuxLinuxf400e12656ab518be107febfe2315fb1eab5a342 < bbb2218eb072b0a15dc063929200183bd23c2344affected
LinuxLinuxf400e12656ab518be107febfe2315fb1eab5a342 < d0a3729d464fcf516416a41cf304c0c92126ee03affected
LinuxLinuxf400e12656ab518be107febfe2315fb1eab5a342 < e4afd90bc7bf3dd477970c6c42bdd29ad3fda7feaffected
LinuxLinuxf400e12656ab518be107febfe2315fb1eab5a342 < e300eb5002925b29be803d2661af07266cfa267eaffected
LinuxLinux2.6.29affected
LinuxLinux0 < 2.6.29unaffected
LinuxLinux5.10.270 <= 5.10.*unaffected
LinuxLinux5.15.221 <= 5.15.*unaffected
LinuxLinux6.1.188 <= 6.1.*unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References