CVE-2025-39735: jfs: fix slab-out-of-bounds read in ea_get()

Published Apr 18, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

jfs: fix slab-out-of-bounds read in eaget()

During the "sizecheck" label in eaget(), the code checks if the extended attribute list (xattr) size matches easize. If not, it logs "eaget: invalid extended attribute" and calls printhexdump().

Here, EALISTSIZE(eabuf->xattr) returns 4110417968, which exceeds INTMAX (2,147,483,647). Then easize is clamped:

int size = clampt(int, easize, 0, EALISTSIZE(eabuf->xattr));

Although clampt aims to bound easize between 0 and 4110417968, the upper limit is treated as an int, causing an overflow above 2^31 - 1. This leads "size" to wrap around and become negative (-184549328).

The "size" is then passed to printhexdump() (called "len" in printhexdump()), it is passed as type sizet (an unsigned type), this is then stored inside a variable called "int remaining", which is then assigned to "int linelen" which is then passed to hexdumptobuffer(). In printhexdump() the for loop, iterates through 0 to len-1, where len is 18446744073525002176, calling hexdumptobuffer() on each iteration:

for (i = 0; i < len; i += rowsize) { linelen = min(remaining, rowsize); remaining -= rowsize;

hexdumptobuffer(ptr + i, linelen, rowsize, groupsize, linebuf, sizeof(linebuf), ascii);

... }

The expected stopping condition (i < len) is effectively broken since len is corrupted and very large. This eventually leads to the "ptr+i" being passed to hexdumptobuffer() to get closer to the end of the actual bounds of "ptr", eventually an out of bounds access is done in hexdumptobuffer() in the following for loop:

for (j = 0; j < len; j++) { if (linebuflen < lx + 2) goto overflow2; ch = ptr[j]; ... }

To fix this we should validate "EALISTSIZE(eabuf->xattr)" before it is utilised.

Affected Software

11 affected components
Linux Linux kernel
Linux Linux kernel>=4.19.325<4.20
Linux Linux kernel>=5.4.287<5.4.292
Linux Linux kernel>=5.10.231<5.10.236
Linux Linux kernel>=5.15.174<5.15.180
Linux Linux kernel>=6.1.120<6.1.134
Linux Linux kernel>=6.6.64<6.6.87
Linux Linux kernel>=6.11.11<6.12
Linux Linux kernel>=6.12.2<6.12.23
Linux Linux kernel>=6.13<6.13.11
Linux Linux kernel>=6.14<6.14.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    In jfs::ea_get(), validate that EALIST_SIZE(ea_buf->xattr) matches the expected ea_size (and/or clamp ea_size using EALIST_SIZE(ea_buf->xattr)) before passing the computed length into print_hex_dump()/hex_dump_to_buffer to prevent overflow/out-of-bounds reads.

    Linux kernel jfs ea_get()/hex dump path EALIST_SIZE(ea_buf->xattr) validation = validated and matched to ea_size before use

Event History

Apr 18, 2025
CVE Published
via MITRE·07:01 AM
Data Sourced
via MITRE·07:01 AM
DescriptionSeverity
Data Sourced
via NVD·07:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
May 5, 2025
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2025-39735?

CVE-2025-39735 is classified with a high severity level due to the potential for a slab-out-of-bounds read which could be exploited.

2

How do I fix CVE-2025-39735?

To fix CVE-2025-39735, ensure that your Linux kernel is updated to the latest patched version that resolves this vulnerability.

3

What systems are affected by CVE-2025-39735?

CVE-2025-39735 specifically affects the Linux kernel where the jfs file system is utilized.

4

What exploit impacts can CVE-2025-39735 have?

CVE-2025-39735 can be exploited to cause denial-of-service or potentially execute arbitrary code due to the slab-out-of-bounds read.

5

When was CVE-2025-39735 disclosed?

CVE-2025-39735 was disclosed as a vulnerability in the Linux kernel related to jfs and its handling of extended attributes.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203