Impact
The Linux kernel’s SquashFS implementation reads a block offset that may be negative. When squashfs_copy_data() processes this negative offset, it performs an out‑of‑bounds read beyond the intended block. This flaw can leak kernel memory or other data stored beyond the block boundary. The vulnerability does not directly enable code execution, but the exposed information could be used to facilitate further attacks such as privilege escalation or detailed system profiling.
Affected Systems
All Linux kernel releases that compile SquashFS and have not yet applied the patch commit are affected. The flaw exists in any kernel configuration where SquashFS support is built-in, regardless of the distribution or vendor. Any user with CAP_SYS_ADMIN can mount a malicious SquashFS filesystem, after which other users may trigger the out‑of‑bounds read by accessing crafted files within the mount.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Exploitation requires an attacker to create a malicious SquashFS image and obtain CAP_SYS_ADMIN privileges to mount it. Once mounted, unprivileged users can trigger the out‑of‑bounds read by accessing the crafted file. The attack vector is local and constrained to systems that allow mounting such filesystems, limiting the potential impact to those environments.
OpenCVE Enrichment
Debian DLA
Debian DSA