Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-40200— Squashfs: reject negative file sizes in squashfs_read_inode()

EPSS 0.20% · P10

Possible ATT&CK Techniques 1AI

T1564.004 · NTFS File Attributes

Affected Version Matrix 18

VendorProductVersion RangeStatus
LinuxLinux6545b246a2c815a8fcd07d58240effb6ec3481b1< 54170057a5fadd24a37b70de41e61d39284d9bd7affected
6545b246a2c815a8fcd07d58240effb6ec3481b1< 2871c74caa3f4f05b429e6bfefebac62dbf1b408affected
6545b246a2c815a8fcd07d58240effb6ec3481b1< fbfc745db628de31f5c089147deeb87e95b89e66affected
6545b246a2c815a8fcd07d58240effb6ec3481b1< 8118f66124895829443d09c207e654adcb2f9321affected
6545b246a2c815a8fcd07d58240effb6ec3481b1< 8c7aad76751816207fee556d44aa88a710824810affected
6545b246a2c815a8fcd07d58240effb6ec3481b1< 875fb3f87ae0225b881319ba016a1a8c4ffd5812affected
6545b246a2c815a8fcd07d58240effb6ec3481b1< f271155ff31aca8ef82c61c8df23ca97e9a77dd4affected
6545b246a2c815a8fcd07d58240effb6ec3481b1< 9f1c14c1de1bdde395f6cc893efa4f80a2ae3b2baffected
… +10 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-40200

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Squashfs: reject negative file sizes in squashfs_read_inode()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: Squashfs: reject negative file sizes in squashfs_read_inode() Syskaller reports a "WARNING in ovl_copy_up_file" in overlayfs. This warning is ultimately caused because the underlying Squashfs file system returns a file with a negative file size. This commit checks for a negative file size and returns EINVAL. [phillip@squashfs.org.uk: only need to check 64 bit quantity]
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于负文件大小检查不足,可能导致文件系统错误。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 6545b246a2c815a8fcd07d58240effb6ec3481b1 ~ 54170057a5fadd24a37b70de41e61d39284d9bd7 -
LinuxLinux 2.6.29 -

II. Public POCs for CVE-2025-40200

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-40200

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-11-12 · 96 CVEs total

CVE-2025-401769.8 CRITICALtls: wait for pending async decryptions if tls_strp_msg_hold fails
CVE-2025-401408.8 HIGHnet: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast
CVE-2025-401338.1 HIGHmptcp: Use __sk_dst_get() and dst_dev_rcu() in mptcp_active_enable().
CVE-2025-402048.1 HIGHsctp: Fix MAC comparison to be constant-time
CVE-2025-401688.1 HIGHsmc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match().
CVE-2025-401588.1 HIGHipv6: use RCU in ip6_output()
CVE-2025-401358.1 HIGHipv6: use RCU in ip6_xmit()
CVE-2025-401868.1 HIGHtcp: Don't call reqsk_fastopen_remove() in tcp_conn_request().
CVE-2025-401418.0 HIGHBluetooth: ISO: Fix possible UAF on iso_conn_free
CVE-2025-401677.8 HIGHext4: detect invalid INLINE_DATA + EXTENTS flag combination
CVE-2025-401597.8 HIGHxsk: Harden userspace-supplied xdp_desc validation
CVE-2025-401667.8 HIGHdrm/xe/guc: Check GuC running state before deregistering exec queue
CVE-2025-401657.8 HIGHmedia: nxp: imx8-isi: m2m: Fix streaming cleanup on release
CVE-2025-401517.8 HIGHLoongArch: BPF: No support of struct argument in trampoline programs
CVE-2025-401497.8 HIGHtls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock().
CVE-2025-401727.8 HIGHaccel/qaic: Treat remaining == 0 as error in find_and_map_user_pages()
CVE-2025-401697.8 HIGHbpf: Reject negative offsets for ALU ops
CVE-2025-402017.8 HIGHkernel/sys.c: fix the racy usage of task_lock(tsk->group_leader) in sys_prlimit64() paths
CVE-2025-402037.8 HIGHlistmount: don't call path_put() under namespace semaphore
CVE-2025-402057.8 HIGHbtrfs: avoid potential out-of-bounds in btrfs_encode_fh()

Showing top 20 of 96 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-40200

No comments yet


Leave a comment