cbcvebase.
CVE-2025-37741
published 2025-05-01

CVE-2025-37741: In the Linux kernel, the following vulnerability has been resolved: jfs: Prevent copying of nlink with value 0 from disk inode syzbot report a deadlock in…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.9th percentile
In the Linux kernel, the following vulnerability has been resolved: jfs: Prevent copying of nlink with value 0 from disk inode syzbot report a deadlock in diFree. [1] When calling "ioctl$LOOP_SET_STATUS64", the offset value passed in is 4, which does not match the mounted loop device, causing the mapping of the mounted loop device to be invalidated. When creating the directory and creating the inode of iag in diReadSpecial(), read the page of fixed disk inode (AIT) in raw mode in read_metapage(), the metapage data it returns is corrupted, which causes the nlink value of 0 to be assigned to the iag inode when executing copy_from_dinode(), which ultimately causes a deadlock when entering diFree(). To avoid this, first check the nlink value of dinode before setting iag inode. [1] WARNING: possible recursive locking detected 6.12.0-rc7-syzkaller-00212-g4a5df3796467 #0 Not tainted syz-executor301/5309 is trying to acquire lock: ffff888044548920 (&(imap->im_aglock[index])){+.+.}-{3:3}, at: diFree+0x37c/0x2fb0 fs/jfs/jfs_imap.c:889 but task is already holding lock: ffff888044548920 (&(imap->im_aglock[index])){+.+.}-{3:3}, at: diAlloc+0x1b6/0x1630 other info that might help us debug this: Possible unsafe locking scenario: CPU0 ---- lock(&(imap->im_aglock[index])); lock(&(imap->im_aglock[index])); *** DEADLOCK *** May be due to missing lock nesting notation 5 locks held by syz-executor301/5309: #0: ffff8880422a4420 (sb_writers#9){.+.+}-{0:0}, at: mnt_want_write+0x3f/0x90 fs/namespace.c:515 #1: ffff88804755b390 (&type->i_mutex_dir_key#6/1){+.+.}-{3:3}, at: inode_lock_nested include/linux/fs.h:850 [inline] #1: ffff88804755b390 (&type->i_mutex_dir_key#6/1){+.+.}-{3:3}, at: filename_create+0x260/0x540 fs/namei.c:4026 #2: ffff888044548920 (&(imap->im_aglock[index])){+.+.}-{3:3}, at: diAlloc+0x1b6/0x1630 #3: ffff888044548890 (&imap->im_freelock){+.+.}-{3:3}, at: diNewIAG fs/jfs/jfs_imap.c:2460 [inline] #3: ffff888044548890 (&imap->im_freelock){+.+.}-{3:3}, at: diAllocE

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5b2f26d3fba4e9aac314f8bc0963b3fc28c0e4565b2f26d3fba4e9aac314f8bc0963b3fc28c0e456
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8b5ce75f8bd3ddf480cc0a240d7ff5cdea0444f98b5ce75f8bd3ddf480cc0a240d7ff5cdea0444f9
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 86bfeaa18f9e4615b97f2d613e0fcc4ced19652786bfeaa18f9e4615b97f2d613e0fcc4ced196527
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < c9541c2bd0edbdbc5c1148a84d3b48dc8d1b8af2c9541c2bd0edbdbc5c1148a84d3b48dc8d1b8af2
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b3c4884b987e5d8d0ec061a4d52653c4f4b9c37eb3c4884b987e5d8d0ec061a4d52653c4f4b9c37e
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < aeb926e605f97857504bdf748f575e40617e2ef9aeb926e605f97857504bdf748f575e40617e2ef9
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 994787341358816d91b2fded288ecb7f129f2b27994787341358816d91b2fded288ecb7f129f2b27
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < a2b560815528ae8e266fca6038bb5585d13aaef4a2b560815528ae8e266fca6038bb5585d13aaef4
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b61e69bb1c049cf507e3c654fa3dc1568231bd07b61e69bb1c049cf507e3c654fa3dc1568231bd07
linuxlinux_kernel< 5.4.2935.4.293
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 5.11 < 5.15.1815.15.181
linuxlinux_kernel>= 5.16 < 6.1.1356.1.135
linuxlinux_kernel>= 5.5 < 5.10.2375.10.237
linuxlinux_kernel>= 6.13 < 6.13.126.13.12

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.