Answer in brief
CVE-2026-90203 records a Unknown severity vulnerability in Squashfs: check block offset is not negative. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f400e12656ab518be107febfe2315fb1eab5a342 <b169185d5c672b989985c6c2e38cafab2548ba88 || >=f400e12656ab518be107febfe2315fb1eab5a342 <c2a126fca820ae74872da28de68dc74d4595dc4b || >=f400e12656ab518be107febfe2315fb1eab5a342 <95dadf366c117dcdca78a570e6832071deab1ecd || >=f400e12656ab518be107febfe2315fb1eab5a342 <3d2f0cb66c909ea2312cdef465165bb9a3ba2d84 || >=f400e12656ab518be107febfe2315fb1eab5a342 <bbb2218eb072b0a15dc063929200183bd23c2344 || >=f400e12656ab518be107febfe2315fb1eab5a342 <d0a3729d464fcf516416a41cf304c0c92126ee03 || >=f400e12656ab518be107febfe2315fb1eab5a342 <e4afd90bc7bf3dd477970c6c42bdd29ad3fda7fe || >=f400e12656ab518be107febfe2315fb1eab5a342 <e300eb5002925b29be803d2661af07266cfa267e | b169185d5c672b989985c6c2e38cafab2548ba88, c2a126fca820ae74872da28de68dc74d4595dc4b, 95dadf366c117dcdca78a570e6832071deab1ecd, 3d2f0cb66c909ea2312cdef465165bb9a3ba2d84, bbb2218eb072b0a15dc063929200183bd23c2344, d0a3729d464fcf516416a41cf304c0c92126ee03, e4afd90bc7bf3dd477970c6c42bdd29ad3fda7fe, e300eb5002925b29be803d2661af07266cfa267e |
| Linux/Linuxgeneric | 2.6.29 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: Squashfs: check block offset is not negative If a negative offset is read off disk (for example the offset into the decompressed fragment block), this will cause squashfs_copy_data() to perform an out of bounds access. Fix by checking if offset is negative, and returning 0. This matches existing behaviour where an offset beyond the block returns 0 bytes copied. To trigger this out of bounds access requires a crafted Squashfs filesystem and CAP_SYS_ADMIN to mount it. Unprivileged users will not be able to mount such a filesystem, but once mounted, an unprivileged user can trigger the out of bounds access by reading the crafted file with the negative offset.
Quoted source text, attributed separately from HOL analysis.