cbcvebase.
CVE-2025-37839
published 2025-05-09

CVE-2025-37839: In the Linux kernel, the following vulnerability has been resolved: jbd2: remove wrong sb->s_sequence check Journal emptiness is not determined by…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.29%
21.3th percentile
In the Linux kernel, the following vulnerability has been resolved: jbd2: remove wrong sb->s_sequence check Journal emptiness is not determined by sb->s_sequence == 0 but rather by sb->s_start == 0 (which is set a few lines above). Furthermore 0 is a valid transaction ID so the check can spuriously trigger. Remove the invalid WARN_ON.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 24bcc89c7e7c64982e6192b4952a0a92379fc341 < cf30432f5b3064ff85d85639c2f0106f89c566f6cf30432f5b3064ff85d85639c2f0106f89c566f6
linuxlinux>= 24bcc89c7e7c64982e6192b4952a0a92379fc341 < b479839525fe7906966cdc4b5b2afbca048558a1b479839525fe7906966cdc4b5b2afbca048558a1
linuxlinux>= 24bcc89c7e7c64982e6192b4952a0a92379fc341 < ad926f735b4d4f10768fec7d080cadeb6d075cacad926f735b4d4f10768fec7d080cadeb6d075cac
linuxlinux>= 24bcc89c7e7c64982e6192b4952a0a92379fc341 < 3b4643ffaf72d7a5a357e9bf68b1775f8cfe7e773b4643ffaf72d7a5a357e9bf68b1775f8cfe7e77
linuxlinux>= 24bcc89c7e7c64982e6192b4952a0a92379fc341 < c88f7328bb0fff66520fc9164f02b1d06e083c1bc88f7328bb0fff66520fc9164f02b1d06e083c1b
linuxlinux>= 24bcc89c7e7c64982e6192b4952a0a92379fc341 < 9eaec071f111cd2124ce9a5b93536d3f6837d4579eaec071f111cd2124ce9a5b93536d3f6837d457
linuxlinux>= 24bcc89c7e7c64982e6192b4952a0a92379fc341 < c98eb9ffb1d9c98237b5e1668eee17654e129fb0c98eb9ffb1d9c98237b5e1668eee17654e129fb0
linuxlinux>= 24bcc89c7e7c64982e6192b4952a0a92379fc341 < b0cca357f85beb6144ab60c62dcc98508cc044bfb0cca357f85beb6144ab60c62dcc98508cc044bf
linuxlinux>= 24bcc89c7e7c64982e6192b4952a0a92379fc341 < e6eff39dd0fe4190c6146069cc16d160e71d1148e6eff39dd0fe4190c6146069cc16d160e71d1148
linuxlinux>= 3.2.71 < 3.33.3
linuxlinux_kernel< 5.4.2935.4.293
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 5.11 < 5.15.1815.15.181
linuxlinux_kernel>= 5.16 < 6.1.1356.1.135

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.