SB2026091909 - Memory corruption in Linux kernel squashfs
Published: September 19, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Memory corruption (CVE-ID: CVE-2026-90203)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause an out-of-bounds memory access.
The vulnerability exists due to improper validation of a negative block offset in squashfs_copy_data() when reading a crafted file from a mounted crafted Squashfs filesystem. A local user can read a crafted file with a negative offset to cause an out-of-bounds memory access.
Mounting the crafted Squashfs filesystem requires CAP_SYS_ADMIN.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3d2f0cb66c909ea2312cdef465165bb9a3ba2d84
- https://git.kernel.org/stable/c/95dadf366c117dcdca78a570e6832071deab1ecd
- https://git.kernel.org/stable/c/b169185d5c672b989985c6c2e38cafab2548ba88
- https://git.kernel.org/stable/c/bbb2218eb072b0a15dc063929200183bd23c2344
- https://git.kernel.org/stable/c/c2a126fca820ae74872da28de68dc74d4595dc4b
- https://git.kernel.org/stable/c/d0a3729d464fcf516416a41cf304c0c92126ee03
- https://git.kernel.org/stable/c/e300eb5002925b29be803d2661af07266cfa267e
- https://git.kernel.org/stable/c/e4afd90bc7bf3dd477970c6c42bdd29ad3fda7fe