PT-2025-28005 · Linux+4 · Linux Kernel+4
Anubis
·
Published
2025-07-04
·
Updated
2026-04-20
·
CVE-2025-38230
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 6.14.0-rc5-syzkaller
Description:
A vulnerability in the Linux kernel has been resolved, which involved validating AG parameters in dbMount() to prevent crashes. The validation checks
db agheight, db agwidth, and db agstart in dbMount to catch corrupted metadata early and avoid undefined behavior in dbAllocAG. The limits for these parameters are derived from L2LPERCTL, LPERCTL/MAXAG, and CTLTREESIZE. The issue was identified by the Linux Verification Center with Syzkaller, and it caused a shift-out-of-bounds error in fs/jfs/jfs dmap.c.Recommendations:
For Linux kernel versions prior to 6.14.0-rc5-syzkaller, update to a newer version to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable
dbMount() function until a patch is available. Avoid using the dbAllocAG() function with corrupted metadata to minimize the risk of exploitation.Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linuxmint
Linux Kernel
Red Os
Ubuntu