Junglewise Threat Intelligence

CVE-2025-38415: Linux Kernel shift-out-of-bounds in Squashfs sb_min_blocksize

CVE-2025-38415 · Severity: high · CVSS 7.8 · Published 2025-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Squashfs file system driver could allow a local user to crash the system. By triggering a specific sequence of operations while mounting a Squashfs file system, an attacker can cause a 'shift-out-of-bounds' error, leading to a kernel panic or system instability. This primarily impacts the availability of the system and any services running on it.

Technical details

A race condition exists in the Squashfs implementation within the Linux kernel. When a process issues a LOOP_SET_BLOCK_SIZE ioctl on a loop device while another process is mounting a Squashfs filesystem on that same device, sb_min_blocksize() may return 0. The squashfs_fill_super() function fails to check this return value and subsequently passes it to ffz(), resulting in a log2 value of 64. This leads to a shift-out-of-bounds error in squashfs_bio_read() when a 64-bit type is shifted by 64. The vulnerability was identified by Syzkaller and is fixed by adding a check for the return value of sb_min_blocksize().

Affected products

  • Linux Linux Kernel All versions prior to the fix in Squashfs component

Timeline

  • 2025-04-09: disclosed: Initial patch submission by Phillip Lougher
  • 2025-06-19: patched: Commits merged into various stable branches
  • 2025-07-25: advisory: CVE-2025-38415 published

References

Related threats