HomeDefectsLIN1024-15990
Acknowledged

LIN1024-15990 : Security Advisory - linux - CVE-2026-23388

Created: Mar 26, 2026    Updated: Mar 31, 2026
Found In Version: 10.24.33.2
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  Squashfs: check metadata block offset is within range  Syzkaller reports a "general protection fault in squashfs_copy_data"  This is ultimately caused by a corrupted index look-up table, which produces a negative metadata block offset.  This is subsequently passed to squashfs_copy_data (via squashfs_read_metadata) where the negative offset causes an out of bounds access.  The fix is to check that the offset is within range in squashfs_read_metadata.  This will trap this and other cases.