KernelScan.io

HIGH Introduced in 2.6.29

squashfs BlockOffset OOB

CVE-2026-90203

CVSS 7.1 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

KernelScan AI6.0MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: Squashfs: check block offset is not negative If a negative offset is read off disk (for example the offset into the decompressed fragment block), this will cause squashfs_copy_data() to perform an out of bounds access. Fix by checking if offset is negative, and returning 0. This matches existing behaviour where an offset beyond the block returns 0 bytes copied. To trigger this out of bounds access requires a crafted Squashfs filesystem and CAP_SYS_ADMIN to mount it. Unprivileged users will not be able to mount such a filesystem, but once mounted, an unprivileged user can trigger the out of bounds access by reading the crafted file with the negative offset.

02

Engine v0.6.0

Risk summary

A crafted Squashfs filesystem image can contain a negative block offset that causes the kernel to read out-of-bounds kernel memory when a file is accessed. Mounting the crafted filesystem requires CAP_SYS_ADMIN, but once mounted any unprivileged user can trigger the OOB read by reading the affected file, potentially leaking kernel memory or crashing the system.

Affectedfs/squashfs/cache.c (squashfs)

Vulnerability analysis

A crafted Squashfs filesystem image can store a negative offset value for a fragment block. When the kernel reads a file that uses this offset, it performs an out-of-bounds read from kernel heap memory before the decompressed block buffer, and the leaked data is copied to the reader's buffer. The fix adds a check that rejects negative offsets early, returning zero bytes copied, which matches the existing behaviour for offsets that exceed the block size. Triggering the bug requires CAP_SYS_ADMIN to mount the crafted Squashfs image (it is not mountable from a user namespace), but once mounted, any unprivileged user can trigger the out-of-bounds access simply by reading the crafted file.

03

BranchIntroducedFixed inPatch commit
5.102.6.295.10.270b169185d5c67
5.152.6.295.15.221c2a126fca820
6.12.6.296.1.18895dadf366c11
6.122.6.296.12.110bbb2218eb072
6.62.6.296.6.1573d2f0cb66c90
6.182.6.296.18.52d0a3729d464f
mainline2.6.297.3-rc1e300eb500292
7.22.6.297.2.6e4afd90bc7bf