CVE-2026-23388 — Improper Validation of Specified Index, Position, or Offset in Input in Linux
Severity
6.3MEDIUM
No vectorEPSS
0.0%
top 90.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 25
Description
In the Linux kernel, the following vulnerability has been resolved:
Squashfs: check metadata block offset is within range
Syzkaller reports a "general protection fault in squashfs_copy_data"
This is ultimately caused by a corrupted index look-up table, which
produces a negative metadata block offset.
This is subsequently passed to squashfs_copy_data (via
squashfs_read_metadata) where the negative offset causes an out of bounds
access.
The fix is to check that the offset is within range in
s…
Affected Packages3 packages
▶CVEListV5linux/linuxf400e12656ab518be107febfe2315fb1eab5a342 — 0c8ab092aec3ac4294940054772d30b511b16713+6
🔴Vulnerability Details
4OSV▶
CVE-2026-23388: In the Linux kernel, the following vulnerability has been resolved: Squashfs: check metadata block offset is within range Syzkaller reports a "general↗2026-03-25
GHSA▶
GHSA-3667-r4r3-59jh: In the Linux kernel, the following vulnerability has been resolved:
Squashfs: check metadata block offset is within range
Syzkaller reports a "gener↗2026-03-25