Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-39735— jfs: fix slab-out-of-bounds read in ea_get()

CVSS 7.1 · High EPSS 0.27% · P20

Affected Version Matrix 30

VendorProductVersion RangeStatus
LinuxLinux6e39b681d1eb16f408493bf5023788b57f68998c< 3d6fd5b9c6acbc005e53d0211c7381f566babec1affected
bbf3f1fd8a0ac7df1db36a9b9e923041a14369f2< 50afcee7011155933d8d5e8832f52eeee018cfd3affected
27a93c45e16ac25a0e2b5e5668e2d1beca56a478< 78c9cbde8880ec02d864c166bcb4fe989ce1d95faffected
9c356fc32a4480a2c0e537a05f2a8617633ddad0< 46e2c031aa59ea65128991cbca474bd5c0c2ecdbaffected
9353cdf28d4c5c0ff19c5df7fbf81ea774de43a4< a8c31808925b11393a6601f534bb63bac5366babaffected
8c505ebeed8045b488b2e60b516c752b851f8437< 0beddc2a3f9b9cf7d8887973041e36c2d0fa3652affected
d9f9d96136cba8fedd647d2c024342ce090133c2< 16d3d36436492aa248b2d8045e75585ebcc2f34daffected
d9f9d96136cba8fedd647d2c024342ce090133c2< 5263822558a8a7c0d0248d5679c2dcf4d5cda61faffected
… +22 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-39735

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
jfs: fix slab-out-of-bounds read in ea_get()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: jfs: fix slab-out-of-bounds read in ea_get() During the "size_check" label in ea_get(), the code checks if the extended attribute list (xattr) size matches ea_size. If not, it logs "ea_get: invalid extended attribute" and calls print_hex_dump(). Here, EALIST_SIZE(ea_buf->xattr) returns 4110417968, which exceeds INT_MAX (2,147,483,647). Then ea_size is clamped: int size = clamp_t(int, ea_size, 0, EALIST_SIZE(ea_buf->xattr)); Although clamp_t aims to bound ea_size between 0 and 4110417968, the upper limit is treated as an int, causing an overflow above 2^31 - 1. This leads "size" to wrap around and become negative (-184549328). The "size" is then passed to print_hex_dump() (called "len" in print_hex_dump()), it is passed as type size_t (an unsigned type), this is then stored inside a variable called "int remaining", which is then assigned to "int linelen" which is then passed to hex_dump_to_buffer(). In print_hex_dump() the for loop, iterates through 0 to len-1, where len is 18446744073525002176, calling hex_dump_to_buffer() on each iteration: for (i = 0; i < len; i += rowsize) { linelen = min(remaining, rowsize); remaining -= rowsize; hex_dump_to_buffer(ptr + i, linelen, rowsize, groupsize, linebuf, sizeof(linebuf), ascii); ... } The expected stopping condition (i < len) is effectively broken since len is corrupted and very large. This eventually leads to the "ptr+i" being passed to hex_dump_to_buffer() to get closer to the end of the actual bounds of "ptr", eventually an out of bounds access is done in hex_dump_to_buffer() in the following for loop: for (j = 0; j < len; j++) { if (linebuflen < lx + 2) goto overflow2; ch = ptr[j]; ... } To fix this we should validate "EALIST_SIZE(ea_buf->xattr)" before it is utilised.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于ea_get未正确处理大尺寸扩展属性,可能导致缓冲区溢出。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 6e39b681d1eb16f408493bf5023788b57f68998c ~ 3d6fd5b9c6acbc005e53d0211c7381f566babec1 -
LinuxLinux 6.13 -

II. Public POCs for CVE-2025-39735

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-39735

登录查看更多情报信息。

Other References for CVE-2025-39735 (7)

Same Patch Batch · Linux · 2025-04-18 · 23 CVEs total

CVE-2025-399308.4 HIGHASoC: simple-card-utils: Don't use __free(device_node) at graph_util_parse_dai()
CVE-2025-403647.8 HIGHio_uring: fix io_req_prep_async with provided buffers
CVE-2025-377857.8 HIGHext4: fix OOB read when checking dotdot dir
CVE-2025-378937.8 HIGHLoongArch: BPF: Fix off-by-one error in build_prologue()
CVE-2025-378387.8 HIGHHSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race Con
CVE-2025-396887.5 HIGHnfsd: allow SC_STATUS_FREEABLE when searching via nfs4_lookup_stateid()
CVE-2025-38479dmaengine: fsl-edma: free irq correctly in remove path
CVE-2025-37860sfc: fix NULL dereferences in ef100_process_design_param()
CVE-2025-37925jfs: reject on-disk inodes of an unsupported type
CVE-2025-40325md/raid10: wait barrier before returning discard request with REQ_NOWAIT
CVE-2025-38049x86/resctrl: Fix allocation of cleanest CLOSID on platforms with no monitors
CVE-2025-38104drm/amdgpu: Replace Mutex with Spinlock for RLCG register access to avoid Priority Inversi
CVE-2025-38152remoteproc: core: Clear table_sz when rproc_shutdown
CVE-2025-38240drm/mediatek: dp: drm_err => dev_err in HPD path to avoid NULL ptr
CVE-2025-40014objtool, spi: amd: Fix out-of-bounds stack access in amd_set_spi_freq()
CVE-2025-38575ksmbd: use aead_request_free to match aead_request_alloc
CVE-2025-38637net_sched: skbprio: Remove overly strict queue assertions
CVE-2025-39728clk: samsung: Fix UBSAN panic in samsung_clk_init()
CVE-2025-39755staging: gpib: Fix cb7210 pcmcia Oops
CVE-2025-39778objtool, nvmet: Fix out-of-bounds stack access in nvmet_ctrl_state_show()

Showing top 20 of 23 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-39735

No comments yet


Leave a comment