We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-52979

squashfs: harden sanity check in squashfs_read_xattr_id_table



Description

In the Linux kernel, the following vulnerability has been resolved: squashfs: harden sanity check in squashfs_read_xattr_id_table While mounting a corrupted filesystem, a signed integer '*xattr_ids' can become less than zero. This leads to the incorrect computation of 'len' and 'indexes' values which can cause null-ptr-deref in copy_bio_to_actor() or out-of-bounds accesses in the next sanity checks inside squashfs_read_xattr_id_table(). Found by Linux Verification Center (linuxtesting.org) with Syzkaller.

Reserved 2025-03-27 | Published 2025-03-27 | Updated 2025-05-04 | Assigner Linux

Product status

Default status
unaffected

ff49cace7b8cf00d27665f7536a863d406963d06 before cf5d6612092408157db6bb500c70bf6d67c40fbc
affected

a8717b34003f4f7353b23826617ad872f85d85d8 before b30a74f83265c24d1d0842c6c3928cd2e775a3fb
affected

3654a0ed0bdc6d70502bfc7c9fec9f1e243dfcad before db76fc535fbdfbf29fd0b93e49627537ad794c8c
affected

bddcce15cd1fb9675ddd46a76d8fe2d0a571313b before de2785aa3448d1ee7be3ab47fd4a873025f1b3d7
affected

506220d2ba21791314af569211ffd8870b8208fa before b7398efe24a965cf3937b716c0b1011c201c5d6e
affected

506220d2ba21791314af569211ffd8870b8208fa before 29e774dcb27116c06b9c57b1f1f14a1623738989
affected

506220d2ba21791314af569211ffd8870b8208fa before 72e544b1b28325fe78a4687b980871a7e4101f76
affected

91d4f4d0d7bcd6abd9f9288ff40f4edc716f3d4b
affected

eca93bf20f70e0f78c8c28720951942f61a49117
affected

Default status
affected

5.11
affected

Any version before 5.11
unaffected

4.14.306
unaffected

4.19.273
unaffected

5.4.232
unaffected

5.10.168
unaffected

5.15.93
unaffected

6.1.11
unaffected

6.2
unaffected

References

git.kernel.org/...c/cf5d6612092408157db6bb500c70bf6d67c40fbc

git.kernel.org/...c/b30a74f83265c24d1d0842c6c3928cd2e775a3fb

git.kernel.org/...c/db76fc535fbdfbf29fd0b93e49627537ad794c8c

git.kernel.org/...c/de2785aa3448d1ee7be3ab47fd4a873025f1b3d7

git.kernel.org/...c/b7398efe24a965cf3937b716c0b1011c201c5d6e

git.kernel.org/...c/29e774dcb27116c06b9c57b1f1f14a1623738989

git.kernel.org/...c/72e544b1b28325fe78a4687b980871a7e4101f76

cve.org (CVE-2023-52979)

nvd.nist.gov (CVE-2023-52979)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2023-52979

Support options

Helpdesk Chat, Email, Knowledgebase