jfs: fix slab-out-of-bounds read in ea_get()
Published Apr 18, 2025
7.1
HIGHCVSS 3.1
EPSS 0.30%
Description
During the "size_check" label in ea_get(), the code checks if the extended attribute list (xattr) size matches ea_size. If not, it logs "ea_get: invalid extended attribute" and calls print_hex_dump().
Here, EALIST_SIZE(ea_buf->xattr) returns 4110417968, which exceeds INT_MAX (2,147,483,647). Then ea_size is clamped:
int size = clamp_t(int, ea_size, 0, EALIST_SIZE(ea_buf->xattr));
Although clamp_t aims to bound ea_size between 0 and 4110417968, the upper limit is treated as an int, causing an overflow above 2^31 - 1. This leads "size" to wrap around and become negative (-184549328).
The "size" is then passed to print_hex_dump() (called "len" in print_hex_dump()), it is passed as type size_t (an unsigned type), this is then stored inside a variable called "int remaining", which is then assigned to "int linelen" which is then passed to hex_dump_to_buffer(). In print_hex_dump() the for loop, iterates through 0 to len-1, where len is 18446744073525002176, calling hex_dump_to_buffer() on each iteration:
for (i = 0; i < len; i += rowsize) { linelen = min(remaining, rowsize); remaining -= rowsize;
hex_dump_to_buffer(ptr + i, linelen, rowsize, groupsize, linebuf, sizeof(linebuf), ascii);
... }
The expected stopping condition (i < len) is effectively broken since len is corrupted and very large. This eventually leads to the "ptr+i" being passed to hex_dump_to_buffer() to get closer to the end of the actual bounds of "ptr", eventually an out of bounds access is done in hex_dump_to_buffer() in the following for loop:
for (j = 0; j < len; j++) { if (linebuflen < lx + 2) goto overflow2; ch = ptr[j]; ... }
To fix this we should validate "EALIST_SIZE(ea_buf->xattr)" before it is utilised.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.19.325StatusaffectedConstraints<4.20
- Version 5.10.231StatusaffectedConstraints<5.10.236
- Version 5.15.174StatusaffectedConstraints<5.15.180
- Version 5.4.287StatusaffectedConstraints<5.4.292
- Version 6.1.120StatusaffectedConstraints<6.1.134
- Version 6.11.11StatusaffectedConstraints<6.12
- Version 6.12.2StatusaffectedConstraints<6.12.23
- Version 6.6.64StatusaffectedConstraints<6.6.87
- Version
-
- Version 6.13StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.13
- Version 5.10.236StatusunaffectedConstraints<=5.10.*
- Version 5.15.180StatusunaffectedConstraints<=5.15.*
- Version 5.4.292StatusunaffectedConstraints<=5.4.*
- Version 6.1.134StatusunaffectedConstraints<=6.1.*
- Version 6.12.23StatusunaffectedConstraints<=6.12.*
- Version 6.13.11StatusunaffectedConstraints<=6.13.*
- Version 6.14.2StatusunaffectedConstraints<=6.14.*
- Version 6.15StatusunaffectedConstraints<=*
- Version 6.6.87StatusunaffectedConstraints<=6.6.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||||||||
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 4.19.325 · < 4.20
- ≥ 5.4.287 · < 5.4.292
- ≥ 5.10.231 · < 5.10.236
- ≥ 5.15.174 · < 5.15.180
- ≥ 6.1.120 · < 6.1.134
- ≥ 6.6.64 · < 6.6.87
- ≥ 6.11.11 · < 6.12
- ≥ 6.12.2 · < 6.12.23
- ≥ 6.13 · < 6.13.11
- ≥ 6.14 · < 6.14.2
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (17)
- https://access.redhat.com/security/cve/CVE-2025-39735 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2360930 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-11818 Advisory
- https://git.kernel.org/stable/c/0beddc2a3f9b9cf7d8887973041e36c2d0fa3652 Patch
- https://git.kernel.org/stable/c/16d3d36436492aa248b2d8045e75585ebcc2f34d Patch
- https://git.kernel.org/stable/c/3d6fd5b9c6acbc005e53d0211c7381f566babec1 Patch
- https://git.kernel.org/stable/c/46e2c031aa59ea65128991cbca474bd5c0c2ecdb Patch
- https://git.kernel.org/stable/c/50afcee7011155933d8d5e8832f52eeee018cfd3 Patch
- https://git.kernel.org/stable/c/5263822558a8a7c0d0248d5679c2dcf4d5cda61f Patch
- https://git.kernel.org/stable/c/78c9cbde8880ec02d864c166bcb4fe989ce1d95f Patch
- https://git.kernel.org/stable/c/a8c31808925b11393a6601f534bb63bac5366bab Patch
- https://git.kernel.org/stable/c/fdf480da5837c23b146c4743c18de97202fcab37 Patch
- https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html
- https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html
- https://lore.kernel.org/linux-cve-announce/2025041820-CVE-2025-39735-41c8@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-39735
- https://www.cve.org/CVERecord?id=CVE-2025-39735
Change history (0)
No recorded changes yet.