Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-39743— jfs: truncate good inode pages when hard link is 0

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于硬链接数为0时未截断inode页面,可能导致触发bugon。

AI Predicted 4.9 Difficulty: Hard EPSS 0.18% · P7

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation

Affected Version Matrix 20

VendorProduct Version RangeStatus
Linux Linux 32983696a48a6c41d99f3eca82ba7510a552d843< 89fff8e3d6710fc32507b8e19eb5afa9fb79b896 affected
32983696a48a6c41d99f3eca82ba7510a552d843< 5845b926c561b8333cd65169526eec357d7bb449 affected
32983696a48a6c41d99f3eca82ba7510a552d843< 8ed7275910fb7177012619864e04d3008763f3ea affected
32983696a48a6c41d99f3eca82ba7510a552d843< b5b471820c33365a8ccd2d463578bf4e47056c2c affected
32983696a48a6c41d99f3eca82ba7510a552d843< 34d8e982bac48bdcca7524644a8825a580edce74 affected
32983696a48a6c41d99f3eca82ba7510a552d843< df3fd8daf278eca365f221749ae5b728e8382a04 affected
32983696a48a6c41d99f3eca82ba7510a552d843< 2b1d5ca395a5fb170c3f885cd42c16179f7f54ec affected
32983696a48a6c41d99f3eca82ba7510a552d843< 1bb5cdc3e39f0c2b311fcb631258b7e60d3fb0d3 affected
… +12 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-39743

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
jfs: truncate good inode pages when hard link is 0
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: jfs: truncate good inode pages when hard link is 0 The fileset value of the inode copy from the disk by the reproducer is AGGR_RESERVED_I. When executing evict, its hard link number is 0, so its inode pages are not truncated. This causes the bugon to be triggered when executing clear_inode() because nrpages is greater than 0.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于硬链接数为0时未截断inode页面,可能导致触发bugon。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 32983696a48a6c41d99f3eca82ba7510a552d843 ~ 89fff8e3d6710fc32507b8e19eb5afa9fb79b896 -
Linux Linux 2.6.14 -

II. Public POCs for CVE-2025-39743

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-39743

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-09-11 · 54 CVEs total

CVE-2025-39758 9.8 CRITICAL RDMA/siw: Fix the sendmsg byte count in siw_tcp_sendpages
CVE-2025-39761 8.8 HIGH wifi: ath12k: Decrement TID on RX peer frag setup error handling
CVE-2025-39750 8.8 HIGH wifi: ath12k: Correct tid cleanup when tid setup fails
CVE-2025-39790 8.4 HIGH bus: mhi: host: Detect events pointing to unexpected TREs
CVE-2025-39779 7.8 HIGH btrfs: subpage: keep TOWRITE tag until folio is cleaned
CVE-2025-39791 7.8 HIGH dm: dm-crypt: Do not partially accept write BIOs with zoned targets
CVE-2025-39780 7.8 HIGH sched/ext: Fix invalid task state transitions on class switch
CVE-2025-39785 7.8 HIGH drm/hisilicon/hibmc: fix irq_request()'s irq name variable is local
CVE-2025-39786 7.8 HIGH iio: adc: ad7173: fix channels index for syscalib_mode
CVE-2025-39787 7.8 HIGH soc: qcom: mdt_loader: Ensure we don't read past the ELF header
CVE-2025-39740 7.8 HIGH drm/xe/migrate: prevent potential UAF
CVE-2025-39770 7.5 HIGH net: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM
CVE-2025-39738 7.3 HIGH btrfs: do not allow relocation of partially dropped subvolumes
CVE-2025-39789 7.3 HIGH crypto: x86/aegis - Add missing error checks
CVE-2025-39776 7.0 HIGH mm/debug_vm_pgtable: clear page table entries at destroy_args()
CVE-2025-39764 netfilter: ctnetlink: remove refcounting in expectation dumpers
CVE-2025-39768 net/mlx5: HWS, fix complex rules rehash error flow
CVE-2025-39773 net: bridge: fix soft lockup in br_multicast_query_expired()
CVE-2025-39772 drm/hisilicon/hibmc: fix the hibmc loaded failed bug
CVE-2025-39769 bnxt_en: Fix lockdep warning during rmmod

Showing top 20 of 54 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-39743

No comments yet


Leave a comment