We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
In the Linux kernel, the following vulnerability has been resolved: squashfs: harden sanity check in squashfs_read_xattr_id_table While mounting a corrupted filesystem, a signed integer '*xattr_ids' can become less than zero. This leads to the incorrect computation of 'len' and 'indexes' values which can cause null-ptr-deref in copy_bio_to_actor() or out-of-bounds accesses in the next sanity checks inside squashfs_read_xattr_id_table(). Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
Reserved 2025-03-27 | Published 2025-03-27 | Updated 2025-05-04 | Assigner Linuxgit.kernel.org/...c/cf5d6612092408157db6bb500c70bf6d67c40fbc
git.kernel.org/...c/b30a74f83265c24d1d0842c6c3928cd2e775a3fb
git.kernel.org/...c/db76fc535fbdfbf29fd0b93e49627537ad794c8c
git.kernel.org/...c/de2785aa3448d1ee7be3ab47fd4a873025f1b3d7
git.kernel.org/...c/b7398efe24a965cf3937b716c0b1011c201c5d6e
git.kernel.org/...c/29e774dcb27116c06b9c57b1f1f14a1623738989
git.kernel.org/...c/72e544b1b28325fe78a4687b980871a7e4101f76
Support options