CVE-2023-52979
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Mar 27, 2025
Updated: Apr 15, 2025
CWE ID 476
Summary
CVE-2023-52979 is a vulnerability affecting the Linux kernel's squashfs file system. A malformed filesystem can cause a signed integer 'xattr_ids' to become negative during mounting, resulting in incorrect computation of 'len' and 'indexes' values. This issue can lead to null pointer dereferencing in copy_bio_to_actor() or out-of-bounds accesses in the subsequent sanity checks within squashfs_read_xattr_id_table(). This vulnerability was discovered by the Linux Verification Center using Syzkaller.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.