CVE-2023-52979 Details
Description
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
A vulnerability in the Linux kernel's Squashfs module can lead to a null pointer dereference or out-of-bounds access. This issue arises when mounting a corrupted filesystem, causing a signed integer, '*xattr_ids', to become negative. The negative value disrupts the calculation of 'len' and 'indexes', which can result in a null pointer dereference in the 'copy_bio_to_actor()' function or out-of-bounds accesses during subsequent sanity checks in 'squashfs_read_xattr_id_table()'. This vulnerability was discovered by the Linux Verification Center using Syzkaller.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
No references are available for this CVE.
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Oct 7, 2025 | CVE Rejected | kernel.org |
| Oct 7, 2025 | CVE Modified | kernel.org |
| Oct 1, 2025 | CVE Modified | CISA-ADP |
| Jun 25, 2025 | Modified Analysis | [email protected] |
| Apr 15, 2025 | Initial Analysis | [email protected] |
| Mar 27, 2025 | New CVE Received | kernel.org |