cbcvebase.
CVE-2026-23388
published 2026-03-25

CVE-2026-23388: In the Linux kernel, the following vulnerability has been resolved: Squashfs: check metadata block offset is within range Syzkaller reports a "general…

PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.12%
2.1th percentile
In the Linux kernel, the following vulnerability has been resolved: Squashfs: check metadata block offset is within range Syzkaller reports a "general protection fault in squashfs_copy_data" This is ultimately caused by a corrupted index look-up table, which produces a negative metadata block offset. This is subsequently passed to squashfs_copy_data (via squashfs_read_metadata) where the negative offset causes an out of bounds access. The fix is to check that the offset is within range in squashfs_read_metadata. This will trap this and other cases.

Affected

63 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.8-1 (forky)linux 6.19.8-1 (forky)
linuxlinux
linuxlinux>= f400e12656ab518be107febfe2315fb1eab5a342 < 60f679f643f3f36a8571ea585e4ce5d93ef952b560f679f643f3f36a8571ea585e4ce5d93ef952b5
linuxlinux>= f400e12656ab518be107febfe2315fb1eab5a342 < 3f68a9457a6190814377577374da75f872e0a0133f68a9457a6190814377577374da75f872e0a013
linuxlinux>= f400e12656ab518be107febfe2315fb1eab5a342 < 0c8ab092aec3ac4294940054772d30b511b167130c8ab092aec3ac4294940054772d30b511b16713
linuxlinux>= f400e12656ab518be107febfe2315fb1eab5a342 < 6b847d65f5b0065e02080c61fad93d57d66863836b847d65f5b0065e02080c61fad93d57d6686383
linuxlinux>= f400e12656ab518be107febfe2315fb1eab5a342 < 9e9fa5ad37c9cbad73c165c7ff1e76e650825e7c9e9fa5ad37c9cbad73c165c7ff1e76e650825e7c
linuxlinux>= f400e12656ab518be107febfe2315fb1eab5a342 < 01ee0bcc29864b78249308e8b35042b09bbf5fe301ee0bcc29864b78249308e8b35042b09bbf5fe3
linuxlinux>= f400e12656ab518be107febfe2315fb1eab5a342 < 3b9499e7d677dd4366239a292238489a804936b23b9499e7d677dd4366239a292238489a804936b2
linuxlinux>= f400e12656ab518be107febfe2315fb1eab5a342 < fdb24a820a5832ec4532273282cbd4f22c291a0dfdb24a820a5832ec4532273282cbd4f22c291a0d
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.8-16.19.8-1
linuxlinux_kernel>= 2.6.29 < 6.1.1676.1.167
linuxlinux_kernel>= 2.6.29.1 < 5.10.2535.10.253
linuxlinux_kernel>= 5.11 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1676.1.167
linuxlinux_kernel>= 6.13 < 6.18.176.18.17
linuxlinux_kernel>= 6.13.0 < 6.18.176.18.17
linuxlinux_kernel>= 6.19 < 6.19.76.19.7
linuxlinux_kernel>= 6.19.0 < 6.19.76.19.7
linuxlinux_kernel>= 6.2 < 6.6.1306.6.130
linuxlinux_kernel>= 6.2.0 < 6.6.1306.6.130
linuxlinux_kernel>= 6.7 < 6.12.776.12.77
linuxlinux_kernel>= 6.7.0 < 6.12.776.12.77

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
vendor_ubuntu7.1HIGH
vendor_redhat6.6MEDIUM
vendor_msrc6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.