CVE-2025-39735
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-39735 is a vulnerability discovered in the Linux kernel affecting the JFS (Journaling File System) component, specifically in the ea_get() function. The vulnerability was disclosed on April 18, 2025, and affects various Linux distributions including Debian and Red Hat systems (NVD, Debian Tracker).

Technical details

The vulnerability is a slab-out-of-bounds read in the eaget() function within the JFS filesystem code. The issue occurs during the 'sizecheck' label in eaget(), where the code checks if the extended attribute list (xattr) size matches easize. The vulnerability stems from EALISTSIZE(eabuf->xattr) returning 4110417968, which exceeds INTMAX (2,147,483,647), leading to an integer overflow when the value is clamped using clampt(). This causes the 'size' variable to wrap around to a negative value (-184549328), which when passed to printhexdump() as an unsigned value, results in an out-of-bounds memory access (NVD).

Impact

The vulnerability allows for a slab-out-of-bounds read in the Linux kernel, which could potentially lead to information disclosure or system crashes. The issue affects multiple Linux distributions including Debian bookworm and bullseye releases (Debian Tracker).

Mitigation and workarounds

The vulnerability has been fixed in various Linux distributions. Debian has released version 6.1.135-1 for the stable distribution (bookworm) to address this issue. Users are recommended to upgrade their Linux packages to the latest versions (Debian Security).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-modules-internal
NoYesDec 09, 2025
CVE-2025-40343N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel
NoYesDec 09, 2025
CVE-2025-40342N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel-matched
NoYesDec 09, 2025
CVE-2025-40341N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-modules-extra
NoYesDec 09, 2025
CVE-2025-40340N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-kvm
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management