HIGH Introduced in 2.6.29
squashfs BlockOffset OOB
CVE-2026-90203
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
KernelScan AI6.0MEDIUM
01Description
In the Linux kernel, the following vulnerability has been resolved: Squashfs: check block offset is not negative If a negative offset is read off disk (for example the offset into the decompressed fragment block), this will cause squashfs_copy_data() to perform an out of bounds access. Fix by checking if offset is negative, and returning 0. This matches existing behaviour where an offset beyond the block returns 0 bytes copied. To trigger this out of bounds access requires a crafted Squashfs filesystem and CAP_SYS_ADMIN to mount it. Unprivileged users will not be able to mount such a filesystem, but once mounted, an unprivileged user can trigger the out of bounds access by reading the crafted file with the negative offset.
02KernelScan AI Analysis
Risk summary
A crafted Squashfs filesystem image can contain a negative block offset that causes the kernel to read out-of-bounds kernel memory when a file is accessed. Mounting the crafted filesystem requires CAP_SYS_ADMIN, but once mounted any unprivileged user can trigger the OOB read by reading the affected file, potentially leaking kernel memory or crashing the system.
Vulnerability analysis
A crafted Squashfs filesystem image can store a negative offset value for a fragment block. When the kernel reads a file that uses this offset, it performs an out-of-bounds read from kernel heap memory before the decompressed block buffer, and the leaked data is copied to the reader's buffer. The fix adds a check that rejects negative offsets early, returning zero bytes copied, which matches the existing behaviour for offsets that exceed the block size. Triggering the bug requires CAP_SYS_ADMIN to mount the crafted Squashfs image (it is not mountable from a user namespace), but once mounted, any unprivileged user can trigger the out-of-bounds access simply by reading the crafted file.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.10 | 2.6.29 | 5.10.270 | b169185d5c67 |
| 5.15 | 2.6.29 | 5.15.221 | c2a126fca820 |
| 6.1 | 2.6.29 | 6.1.188 | 95dadf366c11 |
| 6.12 | 2.6.29 | 6.12.110 | bbb2218eb072 |
| 6.6 | 2.6.29 | 6.6.157 | 3d2f0cb66c90 |
| 6.18 | 2.6.29 | 6.18.52 | d0a3729d464f |
| mainline | 2.6.29 | 7.3-rc1 | e300eb500292 |
| 7.2 | 2.6.29 | 7.2.6 | e4afd90bc7bf |