Memory corruption in Linux kernel - CVE-2026-90203
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local user to cause an out-of-bounds memory access.
The vulnerability exists due to improper validation of a negative block offset in squashfs_copy_data() when reading a crafted file from a mounted crafted Squashfs filesystem. A local user can read a crafted file with a negative offset to cause an out-of-bounds memory access.
Mounting the crafted Squashfs filesystem requires CAP_SYS_ADMIN.
Affected software
How to mitigate CVE-2026-90203
External References
- https://git.kernel.org/stable/c/3d2f0cb66c909ea2312cdef465165bb9a3ba2d84
- https://git.kernel.org/stable/c/95dadf366c117dcdca78a570e6832071deab1ecd
- https://git.kernel.org/stable/c/b169185d5c672b989985c6c2e38cafab2548ba88
- https://git.kernel.org/stable/c/bbb2218eb072b0a15dc063929200183bd23c2344
- https://git.kernel.org/stable/c/c2a126fca820ae74872da28de68dc74d4595dc4b
- https://git.kernel.org/stable/c/d0a3729d464fcf516416a41cf304c0c92126ee03
- https://git.kernel.org/stable/c/e300eb5002925b29be803d2661af07266cfa267e
- https://git.kernel.org/stable/c/e4afd90bc7bf3dd477970c6c42bdd29ad3fda7fe