Junglewise Threat Intelligence

CVE-2025-38698: Linux Kernel JFS corruption check in jfs_open

CVE-2025-38698 · Severity: medium · CVSS 5.5 · Published 2025-09-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's JFS file system component could allow a local user to cause a system crash or operational failure. By creating or accessing a specially crafted, corrupted file on a disk, an attacker can trigger an error that the system does not handle correctly. This primarily impacts the availability of the system.

Technical details

A vulnerability exists in the JFS (Journaled File System) component of the Linux kernel due to insufficient validation of the i_size value in regular files. An attacker with local access can provide a corrupted disk image containing a file with a negative i_size value. When the kernel attempts to open this file via jfs_open, the lack of a sanity check leads to subsequent operation failures and potential kernel instability. The fix introduces a check in fs/jfs/file.c to return an I/O error (-EIO) if a regular file is encountered with a negative size. Patching is available across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel versions from 2.6.12.1 up to (excluding) 5.4.297; 5.5 to 5.10.241; 5.11 to 5.15.190; 5.16 to 6.1.149; 6.2 to 6.6.103; 6.7 to 6.12.43; 6.13 to 6.15.11; 6.16 to 6.16.2

Timeline

  • 2025-09-04: disclosed
  • 2025-07-14: patched: Initial patch in mainline kernel
  • 2025-09-04: advisory

References

Related threats