Junglewise Threat Intelligence

CVE-2025-39924: Linux Kernel EROFS invalid algorithm check in encoded extents

CVE-2025-39924 · Severity: high · CVSS 7.8 · Published 2025-10-01

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's EROFS file system, which is commonly used for read-only data storage in mobile devices and embedded systems. The issue involves improper validation of compressed data structures, which could allow a specially crafted file system image to cause system instability or potentially allow unauthorized access to data. Users are advised to apply kernel updates to ensure the integrity and availability of their systems.

Technical details

A vulnerability exists in the EROFS (Enhanced Read-Only File System) component of the Linux kernel due to insufficient sanity checks in the zmap.c file. Specifically, the algorithm used for encoded extents was not properly validated against Z_EROFS_COMPRESSION_RUNTIME_MAX and sbi->available_compr_algs. An attacker could exploit this by providing a crafted EROFS image with invalid compression metadata, leading to an out-of-bounds access or inconsistent state. The fix introduces a unified sanity check function, z_erofs_map_sanity_check, to ensure algorithm types and cluster sizes are within expected bounds. Patches are available in stable kernel versions 6.16.8 and later.

Affected products

  • Linux Linux Kernel 6.15 to 6.16.7

Timeline

  • 2025-08-24: patched: Initial fix authored by Gao Xiang
  • 2025-10-01: disclosed: CVE-2025-39924 published

References

Related threats