Junglewise Threat Intelligence

CVE-2025-38697: Linux Kernel JFS out-of-bounds access in dbAllocAG

CVE-2025-38697 · Severity: high · CVSS 7.8 · Published 2025-09-04

Technologies: Siemens SIMATIC CN 4100, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability exists in the Linux kernel's JFS file system component, which is responsible for managing data storage on disks. If a user provides a specially crafted or corrupted disk image, the system may attempt to access memory outside of its intended boundaries. This could lead to a system crash, data corruption, or potentially allow an attacker to gain unauthorized access to sensitive information.

Technical details

An improper validation of array index (CWE-129) exists in the JFS (Journaled File System) implementation within the Linux kernel. The vulnerability occurs in the dbAllocAG function in fs/jfs/jfs_dmap.c, where the code fails to perform an upper bound check on the tree index (ti) relative to the size of the stree (dcp->nleafs). A local attacker could exploit this by mounting a specially crafted, corrupted filesystem image to trigger an out-of-bounds read or write. This can result in a kernel panic (denial of service) or potentially privilege escalation. Patches have been released across multiple stable kernel branches including 5.4.y, 5.10.y, and others.

Affected products

  • Linux Linux Kernel 2.6.12 to 6.13.y
  • Siemens SIMATIC CN 4100 before V5.0

Timeline

  • 2025-04-24: disclosed: Vulnerability reported and patch authored
  • 2025-08-28: patched: Patch committed to stable kernel trees
  • 2025-09-04: advisory: CVE published

References

Related threats