Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2025-39735
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-39735 is a vulnerability discovered in the Linux kernel affecting the JFS (Journaling File System) component, specifically in the ea_get() function. The vulnerability was disclosed on April 18, 2025, and affects various Linux distributions including Debian and Red Hat systems (NVD, Debian Tracker).

Technical details

The vulnerability is a slab-out-of-bounds read in the ea_get() function within the JFS filesystem code. The issue occurs during the 'size_check' label in ea_get(), where the code checks if the extended attribute list (xattr) size matches ea_size. The vulnerability stems from EALIST_SIZE(ea_buf->xattr) returning 4110417968, which exceeds INT_MAX (2,147,483,647), leading to an integer overflow when the value is clamped using clamp_t(). This causes the 'size' variable to wrap around to a negative value (-184549328), which when passed to print_hex_dump() as an unsigned value, results in an out-of-bounds memory access (NVD).

Impact

The vulnerability allows for a slab-out-of-bounds read in the Linux kernel, which could potentially lead to information disclosure or system crashes. The issue affects multiple Linux distributions including Debian bookworm and bullseye releases (Debian Tracker).

Exploitability

The vulnerability requires local access to a system with a mounted JFS filesystem to be exploited. It can be triggered through manipulation of extended attributes in the filesystem (NVD).

Mitigation and workarounds

The vulnerability has been fixed in various Linux distributions. Debian has released version 6.1.135-1 for the stable distribution (bookworm) to address this issue. Users are recommended to upgrade their Linux packages to the latest versions (Debian Security).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

linux: 6.1.135-1

Fixed

sid

linux: 6.12.25-1

Fixed

trixie

linux: 6.12.25-1

Fixed

Ubuntu

Fixed

bionic

linux

Not Affected

bionic (esm-infra)

linux-hwe-5.4: 5.4.0-218.238~18.04.1

Fixed

bionic (fips-updates)

linux-fips

Not Affected

bionic (fips)

linux-fips

Not Affected

devel

linux

Not Affected

focal

linux-azure-fde-5.15

Not Affected

focal (esm-infra)

linux: 5.4.0-218.238

Fixed

focal (fips-updates)

linux-fips: 5.4.0-1121.131

Fixed

RHEL / CentOS

Affected

RHEL 8

Not Affected

RHEL 9

Not Affected

RHEL 10

Not Affected

SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93189HIGH8.8
  • Linux Kernel logoLinux Kernel
  • linux-aws-7.0
NoYesSep 17, 2026
CVE-2026-93188MEDIUM6.5
  • Linux Kernel logoLinux Kernel
  • linux-aws-7.0
NoYesSep 17, 2026
CVE-2026-93182NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-hwe-6.17
NoYesSep 17, 2026
CVE-2026-93181NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-nvidia-6.14
NoNoSep 17, 2026
CVE-2026-93174NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-7.0
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management