PT-2025-13325 · Linux+3 · Linux Kernel+3

Published

2023-01-17

·

Updated

2025-05-28

·

CVE-2023-52979

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been identified, specifically in the squashfs component. The issue arises when mounting a corrupted filesystem, causing a signed integer xattr ids to become less than zero. This leads to incorrect computations of len and indexes values, potentially resulting in null pointer dereferences in copy bio to actor() or out-of-bounds accesses in subsequent sanity checks within squashfs read xattr id table(). The vulnerability was discovered by the Linux Verification Center using Syzkaller.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06267
CVE-2023-52979
OPENSUSE-SU-2025_1195-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1195-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:1293-1
SUSE-SU-2025_1195-1
SUSE-SU-2025_1241-1
SUSE-SU-2025_1293-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse