CVE-2025-40200

Description

An integer validation issue was found in the Linux kernel's Squashfs filesystem when reading inode metadata. A local user can trigger this issue by mounting a maliciously crafted Squashfs image containing inodes with negative file sizes. When overlayfs attempts to copy up such files, the negative size value causes warnings in the VFS layer and can lead to unexpected behavior, memory corruption, or denial of service through system instability.

Statement

Squashfs reads on-disk inode structures without validating that file sizes are non-negative. A crafted image with negative file sizes causes warnings when overlayfs attempts copy-up operations, as the negative value confuses VFS copy routines. Depending on how the negative value propagates through size calculations, it can cause buffer operations with nonsensical lengths or other undefined behavior. The fix rejects negative file sizes during inode reading.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score4.4N/AN/A
Attack VectorLocalN/AN/A
Attack ComplexityLowN/AN/A
Privileges RequiredHighN/AN/A
User InteractionNoneN/AN/A
ScopeUnchangedN/AN/A
ConfidentialityNoneN/AN/A
Integrity ImpactNoneN/AN/A
Availability ImpactHighN/AN/A

Vector

Red Hat: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Understanding the Weakness (CWE)

Integrity,Confidentiality,Availability

Technical Impact: Modify Application Data; Execute Unauthorized Code or Commands

An attacker could modify the structure of the message or data being sent to the downstream component, possibly injecting commands.

Availability

Technical Impact: DoS: Resource Consumption (Other)

in some contexts, a negative value could lead to resource consumption.

Confidentiality,Integrity

Technical Impact: Modify Memory; Read Memory

If a negative value is used to access memory, buffers, or other indexable structures, it could access memory outside the bounds of the buffer.

Frequently Asked Questions

Want to get errata notifications? Sign up here.