Executive brief
A vulnerability exists in the Linux kernel's JFS file system component, which is responsible for managing data storage on disks. If a user provides a specially crafted or corrupted disk image, the system may attempt to access memory outside of its intended boundaries. This could lead to a system crash, data corruption, or potentially allow an attacker to gain unauthorized access to sensitive information.
Technical details
An improper validation of array index (CWE-129) exists in the JFS (Journaled File System) implementation within the Linux kernel. The vulnerability occurs in the dbAllocAG function in fs/jfs/jfs_dmap.c, where the code fails to perform an upper bound check on the tree index (ti) relative to the size of the stree (dcp->nleafs). A local attacker could exploit this by mounting a specially crafted, corrupted filesystem image to trigger an out-of-bounds read or write. This can result in a kernel panic (denial of service) or potentially privilege escalation. Patches have been released across multiple stable kernel branches including 5.4.y, 5.10.y, and others.
Affected products
- Linux Linux Kernel 2.6.12 to 6.13.y
- Siemens SIMATIC CN 4100 before V5.0
Timeline
- 2025-04-24: disclosed: Vulnerability reported and patch authored
- 2025-08-28: patched: Patch committed to stable kernel trees
- 2025-09-04: advisory: CVE published
References
- https://git.kernel.org/stable/c/1467a75819e41341cd5ebd16faa2af1ca3c8f4fe
- https://git.kernel.org/stable/c/173cfd741ad7073640bfb7e2344c2a0ee005e769
- https://git.kernel.org/stable/c/2dd05f09cc323018136a7ecdb3d1007be9ede27f
- https://git.kernel.org/stable/c/30e19a884c0b11f33821aacda7e72e914bec26ef
- https://git.kernel.org/stable/c/49ea46d9025aa1914b24ea957636cbe4367a7311
- https://git.kernel.org/stable/c/5bdb9553fb134fd52ec208a8b378120670f6e784
- https://git.kernel.org/stable/c/a4f199203f79ca9cd7355799ccb26800174ff093