Memory Management Vulnerability in Linux Kernel JFS Component
CVE-2025-38230

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 July 2025

What is CVE-2025-38230?

A vulnerability has been identified in the Linux kernel pertaining to the JFS (Journaling File System) component. The issue arises during the validation of allocation group (AG) parameters within the dbMount function. Specifically, the parameters db_agheight, db_agwidth, and db_agstart must be validated to prevent crashes caused by corrupted metadata. Improper handling of these parameters can lead to undefined behavior in subsequent database allocation processes. The validation ensures that the parameters fall within acceptable ranges, leveraging defined limits to maintain system stability. This vulnerability was discovered by the Linux Verification Center using the Syzkaller testing tool.

Affected Version(s)

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 37bfb464ddca87f203071b5bd562cd91ddc0b40a

Linux 2.6.12

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-38230 : Memory Management Vulnerability in Linux Kernel JFS Component