cbcvebase.
CVE-2025-39735
published 2025-04-18

CVE-2025-39735: In the Linux kernel, the following vulnerability has been resolved: jfs: fix slab-out-of-bounds read in ea_get() During the "size_check" label in ea_get(), the…

PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.24%
15.9th percentile
In the Linux kernel, the following vulnerability has been resolved: jfs: fix slab-out-of-bounds read in ea_get() During the "size_check" label in ea_get(), the code checks if the extended attribute list (xattr) size matches ea_size. If not, it logs "ea_get: invalid extended attribute" and calls print_hex_dump(). Here, EALIST_SIZE(ea_buf->xattr) returns 4110417968, which exceeds INT_MAX (2,147,483,647). Then ea_size is clamped: int size = clamp_t(int, ea_size, 0, EALIST_SIZE(ea_buf->xattr)); Although clamp_t aims to bound ea_size between 0 and 4110417968, the upper limit is treated as an int, causing an overflow above 2^31 - 1. This leads "size" to wrap around and become negative (-184549328). The "size" is then passed to print_hex_dump() (called "len" in print_hex_dump()), it is passed as type size_t (an unsigned type), this is then stored inside a variable called "int remaining", which is then assigned to "int linelen" which is then passed to hex_dump_to_buffer(). In print_hex_dump() the for loop, iterates through 0 to len-1, where len is 18446744073525002176, calling hex_dump_to_buffer() on each iteration: for (i = 0; i xattr)" before it is utilised.

Affected

44 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 27a93c45e16ac25a0e2b5e5668e2d1beca56a478 < 78c9cbde8880ec02d864c166bcb4fe989ce1d95f78c9cbde8880ec02d864c166bcb4fe989ce1d95f
linuxlinux>= 4.19.325 < 4.204.20
linuxlinux>= 5.10.231 < 5.10.2365.10.236
linuxlinux>= 5.15.174 < 5.15.1805.15.180
linuxlinux>= 5.4.287 < 5.4.2925.4.292
linuxlinux>= 6.1.120 < 6.1.1346.1.134
linuxlinux>= 6.11.11 < 6.126.12
linuxlinux>= 6.12.2 < 6.12.236.12.23
linuxlinux>= 6.6.64 < 6.6.876.6.87
linuxlinux>= 6e39b681d1eb16f408493bf5023788b57f68998c < 3d6fd5b9c6acbc005e53d0211c7381f566babec13d6fd5b9c6acbc005e53d0211c7381f566babec1
linuxlinux>= 8c505ebeed8045b488b2e60b516c752b851f8437 < 0beddc2a3f9b9cf7d8887973041e36c2d0fa36520beddc2a3f9b9cf7d8887973041e36c2d0fa3652
linuxlinux>= 9353cdf28d4c5c0ff19c5df7fbf81ea774de43a4 < a8c31808925b11393a6601f534bb63bac5366baba8c31808925b11393a6601f534bb63bac5366bab
linuxlinux>= 9c356fc32a4480a2c0e537a05f2a8617633ddad0 < 46e2c031aa59ea65128991cbca474bd5c0c2ecdb46e2c031aa59ea65128991cbca474bd5c0c2ecdb
linuxlinux>= bbf3f1fd8a0ac7df1db36a9b9e923041a14369f2 < 50afcee7011155933d8d5e8832f52eeee018cfd350afcee7011155933d8d5e8832f52eeee018cfd3
linuxlinux>= d9f9d96136cba8fedd647d2c024342ce090133c2 < 16d3d36436492aa248b2d8045e75585ebcc2f34d16d3d36436492aa248b2d8045e75585ebcc2f34d
linuxlinux>= d9f9d96136cba8fedd647d2c024342ce090133c2 < 5263822558a8a7c0d0248d5679c2dcf4d5cda61f5263822558a8a7c0d0248d5679c2dcf4d5cda61f
linuxlinux>= d9f9d96136cba8fedd647d2c024342ce090133c2 < fdf480da5837c23b146c4743c18de97202fcab37fdf480da5837c23b146c4743c18de97202fcab37
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.1HIGH
vendor_msrc7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.