Executive brief
A vulnerability in the Linux kernel's Squashfs file system driver could allow a local user to crash the system. By triggering a specific sequence of operations while mounting a Squashfs file system, an attacker can cause a 'shift-out-of-bounds' error, leading to a kernel panic or system instability. This primarily impacts the availability of the system and any services running on it.
Technical details
A race condition exists in the Squashfs implementation within the Linux kernel. When a process issues a LOOP_SET_BLOCK_SIZE ioctl on a loop device while another process is mounting a Squashfs filesystem on that same device, sb_min_blocksize() may return 0. The squashfs_fill_super() function fails to check this return value and subsequently passes it to ffz(), resulting in a log2 value of 64. This leads to a shift-out-of-bounds error in squashfs_bio_read() when a 64-bit type is shifted by 64. The vulnerability was identified by Syzkaller and is fixed by adding a check for the return value of sb_min_blocksize().
Affected products
- Linux Linux Kernel All versions prior to the fix in Squashfs component
Timeline
- 2025-04-09: disclosed: Initial patch submission by Phillip Lougher
- 2025-06-19: patched: Commits merged into various stable branches
- 2025-07-25: advisory: CVE-2025-38415 published
References
- https://git.kernel.org/stable/c/0aff95d9bc7fb5400ca8af507429c4b067bdb425
- https://git.kernel.org/stable/c/295ab18c2dbce8d0ac6ecf7c5187e16e1ac8b282
- https://git.kernel.org/stable/c/4f99357dadbf9c979ad737156ad4c37fadf7c56b
- https://git.kernel.org/stable/c/549f9e3d7b60d53808c98b9fde49b4f46d0524a5
- https://git.kernel.org/stable/c/5c51aa862cbeed2f3887f0382a2708956710bd68
- https://git.kernel.org/stable/c/6abf6b78c6fb112eee495f5636ffcc350dd2ce25
- https://git.kernel.org/stable/c/734aa85390ea693bb7eaf2240623d41b03705c84