CVE-2025-39735

Source
https://cve.org/CVERecord?id=CVE-2025-39735
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-39735.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-39735
Downstream
Related
Published
2025-04-18T07:01:36.453Z
Modified
2026-03-20T12:43:02.042704Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
jfs: fix slab-out-of-bounds read in ea_get()
Details

In the Linux kernel, the following vulnerability has been resolved:

jfs: fix slab-out-of-bounds read in ea_get()

During the "sizecheck" label in eaget(), the code checks if the extended attribute list (xattr) size matches easize. If not, it logs "eaget: invalid extended attribute" and calls printhexdump().

Here, EALISTSIZE(eabuf->xattr) returns 4110417968, which exceeds INTMAX (2,147,483,647). Then easize is clamped:

int size = clamp_t(int, ea_size, 0, EALIST_SIZE(ea_buf->xattr));

Although clampt aims to bound easize between 0 and 4110417968, the upper limit is treated as an int, causing an overflow above 2^31 - 1. This leads "size" to wrap around and become negative (-184549328).

The "size" is then passed to printhexdump() (called "len" in printhexdump()), it is passed as type sizet (an unsigned type), this is then stored inside a variable called "int remaining", which is then assigned to "int linelen" which is then passed to hexdumptobuffer(). In printhexdump() the for loop, iterates through 0 to len-1, where len is 18446744073525002176, calling hexdumpto_buffer() on each iteration:

for (i = 0; i < len; i += rowsize) {
    linelen = min(remaining, rowsize);
    remaining -= rowsize;

    hex_dump_to_buffer(ptr + i, linelen, rowsize, groupsize,
               linebuf, sizeof(linebuf), ascii);

    ...
}

The expected stopping condition (i < len) is effectively broken since len is corrupted and very large. This eventually leads to the "ptr+i" being passed to hexdumptobuffer() to get closer to the end of the actual bounds of "ptr", eventually an out of bounds access is done in hexdumptobuffer() in the following for loop:

for (j = 0; j < len; j++) {
        if (linebuflen < lx + 2)
            goto overflow2;
        ch = ptr[j];
    ...
}

To fix this we should validate "EALISTSIZE(eabuf->xattr)" before it is utilised.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/39xxx/CVE-2025-39735.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6e39b681d1eb16f408493bf5023788b57f68998c
Fixed
3d6fd5b9c6acbc005e53d0211c7381f566babec1
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bbf3f1fd8a0ac7df1db36a9b9e923041a14369f2
Fixed
50afcee7011155933d8d5e8832f52eeee018cfd3
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
27a93c45e16ac25a0e2b5e5668e2d1beca56a478
Fixed
78c9cbde8880ec02d864c166bcb4fe989ce1d95f
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9c356fc32a4480a2c0e537a05f2a8617633ddad0
Fixed
46e2c031aa59ea65128991cbca474bd5c0c2ecdb
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9353cdf28d4c5c0ff19c5df7fbf81ea774de43a4
Fixed
a8c31808925b11393a6601f534bb63bac5366bab
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8c505ebeed8045b488b2e60b516c752b851f8437
Fixed
0beddc2a3f9b9cf7d8887973041e36c2d0fa3652
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d9f9d96136cba8fedd647d2c024342ce090133c2
Fixed
16d3d36436492aa248b2d8045e75585ebcc2f34d
Fixed
5263822558a8a7c0d0248d5679c2dcf4d5cda61f
Fixed
fdf480da5837c23b146c4743c18de97202fcab37
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
4ea25fa8747fb8b1e5a11d87b852023ecf7ae420
Last affected
676a787048aafd4d1b38a522b05a9cc77e1b0a33

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-39735.json"