Executive brief
A vulnerability in the Linux kernel's JFS file system component could allow a local user to cause a system crash or operational failure. By creating or accessing a specially crafted, corrupted file on a disk, an attacker can trigger an error that the system does not handle correctly. This primarily impacts the availability of the system.
Technical details
A vulnerability exists in the JFS (Journaled File System) component of the Linux kernel due to insufficient validation of the i_size value in regular files. An attacker with local access can provide a corrupted disk image containing a file with a negative i_size value. When the kernel attempts to open this file via jfs_open, the lack of a sanity check leads to subsequent operation failures and potential kernel instability. The fix introduces a check in fs/jfs/file.c to return an I/O error (-EIO) if a regular file is encountered with a negative size. Patching is available across multiple stable kernel branches.
Affected products
- Linux Linux Kernel versions from 2.6.12.1 up to (excluding) 5.4.297; 5.5 to 5.10.241; 5.11 to 5.15.190; 5.16 to 6.1.149; 6.2 to 6.6.103; 6.7 to 6.12.43; 6.13 to 6.15.11; 6.16 to 6.16.2
Timeline
- 2025-09-04: disclosed
- 2025-07-14: patched: Initial patch in mainline kernel
- 2025-09-04: advisory
References
- https://git.kernel.org/stable/c/00462be586b33076f8b8023e7ba697deedc131db
- https://git.kernel.org/stable/c/02edcfda419168d9405bffe55f18ea9c1bf92366
- https://git.kernel.org/stable/c/2d04df8116426b6c7b9f8b9b371250f666a2a2fb
- https://git.kernel.org/stable/c/6bc86f1d7d5419d5b19483ba203ca0b760c41c51
- https://git.kernel.org/stable/c/78989af5bbf55a0cf1165b0fa73921bc02f1543b
- https://git.kernel.org/stable/c/9605cb2ea38ba014d0e704cba0dbbb00593fa9fd
- https://git.kernel.org/stable/c/9ad054cd2c4ca8c371e555748832aa217c41fc65