In the Linux kernel, the following vulnerability has been resolved:
jfs: upper bound check of tree index in dbAllocAG
When computing the tree index in dbAllocAG, we never check if we are out of bounds realative to the size of the stree. This could happen in a scenario where the filesystem metadata are corrupted.
[
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5bdb9553fb134fd52ec208a8b378120670f6e784",
"deprecated": false,
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"309856049866342509725798327169682497116",
"24062441825334502293777560522776722753",
"198385365170970029598986200948761467815"
]
},
"id": "CVE-2025-38697-076f3999",
"signature_version": "v1",
"target": {
"file": "fs/jfs/jfs_dmap.c"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a4f199203f79ca9cd7355799ccb26800174ff093",
"deprecated": false,
"signature_type": "Function",
"digest": {
"function_hash": "191554163171018329408793401449846957632",
"length": 2526.0
},
"id": "CVE-2025-38697-0861a3bf",
"signature_version": "v1",
"target": {
"function": "dbAllocAG",
"file": "fs/jfs/jfs_dmap.c"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@49ea46d9025aa1914b24ea957636cbe4367a7311",
"deprecated": false,
"signature_type": "Function",
"digest": {
"function_hash": "191554163171018329408793401449846957632",
"length": 2526.0
},
"id": "CVE-2025-38697-1684fdc9",
"signature_version": "v1",
"target": {
"function": "dbAllocAG",
"file": "fs/jfs/jfs_dmap.c"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5bdb9553fb134fd52ec208a8b378120670f6e784",
"deprecated": false,
"signature_type": "Function",
"digest": {
"function_hash": "191554163171018329408793401449846957632",
"length": 2526.0
},
"id": "CVE-2025-38697-2d40d2f0",
"signature_version": "v1",
"target": {
"function": "dbAllocAG",
"file": "fs/jfs/jfs_dmap.c"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@173cfd741ad7073640bfb7e2344c2a0ee005e769",
"deprecated": false,
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"309856049866342509725798327169682497116",
"24062441825334502293777560522776722753",
"198385365170970029598986200948761467815"
]
},
"id": "CVE-2025-38697-3ee4a483",
"signature_version": "v1",
"target": {
"file": "fs/jfs/jfs_dmap.c"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c8ca21a2836993d7cb816668458e05e598574e55",
"deprecated": false,
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"309856049866342509725798327169682497116",
"24062441825334502293777560522776722753",
"198385365170970029598986200948761467815"
]
},
"id": "CVE-2025-38697-4051add3",
"signature_version": "v1",
"target": {
"file": "fs/jfs/jfs_dmap.c"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@49ea46d9025aa1914b24ea957636cbe4367a7311",
"deprecated": false,
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"309856049866342509725798327169682497116",
"24062441825334502293777560522776722753",
"198385365170970029598986200948761467815"
]
},
"id": "CVE-2025-38697-4dac3688",
"signature_version": "v1",
"target": {
"file": "fs/jfs/jfs_dmap.c"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c214006856ff52a8ff17ed8da52d50601d54f9ce",
"deprecated": false,
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"309856049866342509725798327169682497116",
"24062441825334502293777560522776722753",
"198385365170970029598986200948761467815"
]
},
"id": "CVE-2025-38697-6bd28342",
"signature_version": "v1",
"target": {
"file": "fs/jfs/jfs_dmap.c"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c8ca21a2836993d7cb816668458e05e598574e55",
"deprecated": false,
"signature_type": "Function",
"digest": {
"function_hash": "191554163171018329408793401449846957632",
"length": 2526.0
},
"id": "CVE-2025-38697-6d45082e",
"signature_version": "v1",
"target": {
"function": "dbAllocAG",
"file": "fs/jfs/jfs_dmap.c"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1467a75819e41341cd5ebd16faa2af1ca3c8f4fe",
"deprecated": false,
"signature_type": "Function",
"digest": {
"function_hash": "191554163171018329408793401449846957632",
"length": 2526.0
},
"id": "CVE-2025-38697-868f8778",
"signature_version": "v1",
"target": {
"function": "dbAllocAG",
"file": "fs/jfs/jfs_dmap.c"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2dd05f09cc323018136a7ecdb3d1007be9ede27f",
"deprecated": false,
"signature_type": "Function",
"digest": {
"function_hash": "191554163171018329408793401449846957632",
"length": 2526.0
},
"id": "CVE-2025-38697-aa6090c5",
"signature_version": "v1",
"target": {
"function": "dbAllocAG",
"file": "fs/jfs/jfs_dmap.c"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c214006856ff52a8ff17ed8da52d50601d54f9ce",
"deprecated": false,
"signature_type": "Function",
"digest": {
"function_hash": "191554163171018329408793401449846957632",
"length": 2526.0
},
"id": "CVE-2025-38697-ab745114",
"signature_version": "v1",
"target": {
"function": "dbAllocAG",
"file": "fs/jfs/jfs_dmap.c"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1467a75819e41341cd5ebd16faa2af1ca3c8f4fe",
"deprecated": false,
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"309856049866342509725798327169682497116",
"24062441825334502293777560522776722753",
"198385365170970029598986200948761467815"
]
},
"id": "CVE-2025-38697-ad195971",
"signature_version": "v1",
"target": {
"file": "fs/jfs/jfs_dmap.c"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a4f199203f79ca9cd7355799ccb26800174ff093",
"deprecated": false,
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"309856049866342509725798327169682497116",
"24062441825334502293777560522776722753",
"198385365170970029598986200948761467815"
]
},
"id": "CVE-2025-38697-b8aedaa7",
"signature_version": "v1",
"target": {
"file": "fs/jfs/jfs_dmap.c"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@173cfd741ad7073640bfb7e2344c2a0ee005e769",
"deprecated": false,
"signature_type": "Function",
"digest": {
"function_hash": "191554163171018329408793401449846957632",
"length": 2526.0
},
"id": "CVE-2025-38697-c93514fb",
"signature_version": "v1",
"target": {
"function": "dbAllocAG",
"file": "fs/jfs/jfs_dmap.c"
}
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2dd05f09cc323018136a7ecdb3d1007be9ede27f",
"deprecated": false,
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"309856049866342509725798327169682497116",
"24062441825334502293777560522776722753",
"198385365170970029598986200948761467815"
]
},
"id": "CVE-2025-38697-e37a150e",
"signature_version": "v1",
"target": {
"file": "fs/jfs/jfs_dmap.c"
}
}
]