CVE-2023-52979

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Mar 27, 2025
Updated: Apr 15, 2025
CWE ID 476

Summary

CVE-2023-52979 is a vulnerability affecting the Linux kernel's squashfs file system. A malformed filesystem can cause a signed integer 'xattr_ids' to become negative during mounting, resulting in incorrect computation of 'len' and 'indexes' values. This issue can lead to null pointer dereferencing in copy_bio_to_actor() or out-of-bounds accesses in the subsequent sanity checks within squashfs_read_xattr_id_table(). This vulnerability was discovered by the Linux Verification Center using Syzkaller.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share