Executive brief
A vulnerability exists in the Linux kernel's JFS file system component. A local user could potentially trigger a system crash or other unintended behavior when the system attempts to clean up certain file metadata (inodes). This occurs because the system fails to properly clear memory pages associated with a file when its last link is removed, leading to an internal kernel error.
Technical details
A vulnerability in the JFS file system implementation in the Linux kernel arises during the inode eviction process. When an inode's hard link count reaches zero, the `jfs_evict_inode` function fails to truncate inode pages if the fileset value is set to `AGGR_RESERVED_I`. This results in `nrpages` being greater than zero when `clear_inode()` is subsequently called, triggering a `BUG_ON()`. An attacker with local access could exploit this by providing a specially crafted disk image or manipulating file links to cause a kernel panic. The issue has been resolved by moving the `truncate_inode_pages_final` call to ensure it executes regardless of the fileset type when the link count is zero.
Affected products
- Linux Linux Kernel 2.6.14 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2
Timeline
- 2025-06-13: other: Patch authored
- 2025-09-11: disclosed: CVE published
- 2025-08-20: patched: Fix committed to stable branches
References
- https://git.kernel.org/stable/c/1bb5cdc3e39f0c2b311fcb631258b7e60d3fb0d3
- https://git.kernel.org/stable/c/2b1d5ca395a5fb170c3f885cd42c16179f7f54ec
- https://git.kernel.org/stable/c/2d91b3765cd05016335cd5df5e5c6a29708ec058
- https://git.kernel.org/stable/c/34d8e982bac48bdcca7524644a8825a580edce74
- https://git.kernel.org/stable/c/5845b926c561b8333cd65169526eec357d7bb449
- https://git.kernel.org/stable/c/89fff8e3d6710fc32507b8e19eb5afa9fb79b896
- https://git.kernel.org/stable/c/8ed7275910fb7177012619864e04d3008763f3ea