U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

CVE-2023-52979 Detail

Description

In the Linux kernel, the following vulnerability has been resolved: squashfs: harden sanity check in squashfs_read_xattr_id_table While mounting a corrupted filesystem, a signed integer '*xattr_ids' can become less than zero. This leads to the incorrect computation of 'len' and 'indexes' values which can cause null-ptr-deref in copy_bio_to_actor() or out-of-bounds accesses in the next sanity checks inside squashfs_read_xattr_id_table(). Found by Linux Verification Center (linuxtesting.org) with Syzkaller.


Metrics

NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 4.0 Severity and Vector Strings:

NIST CVSS score
NIST: NVD
N/A
NVD assessment not yet provided.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.

Hyperlink Resource
https://git.kernel.org/stable/c/29e774dcb27116c06b9c57b1f1f14a1623738989
https://git.kernel.org/stable/c/72e544b1b28325fe78a4687b980871a7e4101f76
https://git.kernel.org/stable/c/b30a74f83265c24d1d0842c6c3928cd2e775a3fb
https://git.kernel.org/stable/c/b7398efe24a965cf3937b716c0b1011c201c5d6e
https://git.kernel.org/stable/c/cf5d6612092408157db6bb500c70bf6d67c40fbc
https://git.kernel.org/stable/c/db76fc535fbdfbf29fd0b93e49627537ad794c8c
https://git.kernel.org/stable/c/de2785aa3448d1ee7be3ab47fd4a873025f1b3d7

Weakness Enumeration

CWE-ID CWE Name Source

Change History

1 change records found show changes

Quick Info

CVE Dictionary Entry:
CVE-2023-52979
NVD Published Date:
03/27/2025
NVD Last Modified:
03/28/2025
Source:
kernel.org