In the Linux kernel, the following vulnerability has been resolved:
Squashfs: reject negative file sizes in squashfs_read_inode()
Syskaller reports a "WARNING in ovl_copy_up_file" in overlayfs.
This warning is ultimately caused because the underlying Squashfs file
system returns a file with a negative file size.
This commit checks for a negative file size and returns EINVAL.
[phillip@squashfs.org.uk: only need to check 64 bit quantity]
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2025-11-12 22:15
Updated : 2026-06-17 09:21
NVD link : CVE-2025-40200
Mitre link : CVE-2025-40200
CVE.ORG link : CVE-2025-40200
JSON object : View
Products Affected
No product.
CWE
No CWE.
