CVE-2026-23388: Linux Kernel
High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: Squashfs: check metadata block offset is within range Syzkaller reports a "general protection fault in squashfs_copy_data" This is ultimately caused by a corrupted index look-up table, which produces a negative metadata block offset. This is subsequently passed to squashfs_copy_data (via squashfs_read_metadata) where the negative offset causes an out of bounds access. The fix is to check that the offset is within range in squashfs_read_metadata. This will trap this and other cases.
Affected products
- Linux Linux Kernel: from 2.6.29.1, before 5.10.253 (fixed in 5.10.253); from 5.11, before 5.15.203 (fixed in 5.15.203); from 5.16, before 6.1.167 (fixed in 6.1.167); from 6.2, before 6.6.130 (fixed in 6.6.130); from 6.7, before 6.12.77 (fixed in 6.12.77); from 6.13, before 6.18.17 (fixed in 6.18.17); …
Published 2026-03-25. Last modified 2026-06-17.