Description
In the Linux kernel, the following vulnerability has been resolved:

Squashfs: check block offset is not negative

If a negative offset is read off disk (for example the offset into the
decompressed fragment block), this will cause squashfs_copy_data() to
perform an out of bounds access.

Fix by checking if offset is negative, and returning 0. This matches
existing behaviour where an offset beyond the block returns 0 bytes
copied.

To trigger this out of bounds access requires a crafted Squashfs
filesystem and CAP_SYS_ADMIN to mount it. Unprivileged users will not be
able to mount such a filesystem, but once mounted, an unprivileged user
can trigger the out of bounds access by reading the crafted file with the
negative offset.
Published: 2026-09-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Out‑of‑bounds read in SquashFS potentially exposing kernel data
Action: Update Kernel
AI Analysis

Impact

The Linux kernel’s SquashFS implementation reads a block offset that may be negative. When squashfs_copy_data() processes this negative offset, it performs an out‑of‑bounds read beyond the intended block. This flaw can leak kernel memory or other data stored beyond the block boundary. The vulnerability does not directly enable code execution, but the exposed information could be used to facilitate further attacks such as privilege escalation or detailed system profiling.

Affected Systems

All Linux kernel releases that compile SquashFS and have not yet applied the patch commit are affected. The flaw exists in any kernel configuration where SquashFS support is built-in, regardless of the distribution or vendor. Any user with CAP_SYS_ADMIN can mount a malicious SquashFS filesystem, after which other users may trigger the out‑of‑bounds read by accessing crafted files within the mount.

Risk and Exploitability

The CVSS score of 7.1 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Exploitation requires an attacker to create a malicious SquashFS image and obtain CAP_SYS_ADMIN privileges to mount it. Once mounted, unprivileged users can trigger the out‑of‑bounds read by accessing the crafted file. The attack vector is local and constrained to systems that allow mounting such filesystems, limiting the potential impact to those environments.

Generated by OpenCVE AI on September 20, 2026 at 01:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes the SquashFS patch for CVE-2026-90203.
  • Restrict the ability to mount SquashFS filesystems so that only users with CAP_SYS_ADMIN or root can do so; enforce this restriction via AppArmor, SELinux, or custom udev rules.
  • Configure audit rules or monitoring to detect the mounting of SquashFS filesystems, especially from untrusted sources, and review logs for anomalous read operations that might indicate exploitation.

Generated by OpenCVE AI on September 20, 2026 at 01:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-190

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: Squashfs: check block offset is not negative If a negative offset is read off disk (for example the offset into the decompressed fragment block), this will cause squashfs_copy_data() to perform an out of bounds access. Fix by checking if offset is negative, and returning 0. This matches existing behaviour where an offset beyond the block returns 0 bytes copied. To trigger this out of bounds access requires a crafted Squashfs filesystem and CAP_SYS_ADMIN to mount it. Unprivileged users will not be able to mount such a filesystem, but once mounted, an unprivileged user can trigger the out of bounds access by reading the crafted file with the negative offset.
Title Squashfs: check block offset is not negative
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:41.435Z

Reserved: 2026-09-11T19:38:34.792Z

Link: CVE-2026-90203

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:15.320

Modified: 2026-09-18T18:17:46.120

Link: CVE-2026-90203

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:30:16Z

Weaknesses