In the Linux kernel, the following vulnerability has been resolved:
jfs: upper bound check of tree index in dbAllocAG
When computing the tree index in dbAllocAG, we never check if we are out of bounds realative to the size of the stree. This could happen in a scenario where the filesystem metadata are corrupted.
[
{
"id": "CVE-2025-38697-1684fdc9",
"signature_version": "v1",
"digest": {
"function_hash": "191554163171018329408793401449846957632",
"length": 2526.0
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@49ea46d9025aa1914b24ea957636cbe4367a7311",
"target": {
"file": "fs/jfs/jfs_dmap.c",
"function": "dbAllocAG"
}
},
{
"id": "CVE-2025-38697-3ee4a483",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"309856049866342509725798327169682497116",
"24062441825334502293777560522776722753",
"198385365170970029598986200948761467815"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@173cfd741ad7073640bfb7e2344c2a0ee005e769",
"target": {
"file": "fs/jfs/jfs_dmap.c"
}
},
{
"id": "CVE-2025-38697-4051add3",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"309856049866342509725798327169682497116",
"24062441825334502293777560522776722753",
"198385365170970029598986200948761467815"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c8ca21a2836993d7cb816668458e05e598574e55",
"target": {
"file": "fs/jfs/jfs_dmap.c"
}
},
{
"id": "CVE-2025-38697-4dac3688",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"309856049866342509725798327169682497116",
"24062441825334502293777560522776722753",
"198385365170970029598986200948761467815"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@49ea46d9025aa1914b24ea957636cbe4367a7311",
"target": {
"file": "fs/jfs/jfs_dmap.c"
}
},
{
"id": "CVE-2025-38697-5f82ca01",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"309856049866342509725798327169682497116",
"24062441825334502293777560522776722753",
"198385365170970029598986200948761467815"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@30e19a884c0b11f33821aacda7e72e914bec26ef",
"target": {
"file": "fs/jfs/jfs_dmap.c"
}
},
{
"id": "CVE-2025-38697-6d45082e",
"signature_version": "v1",
"digest": {
"function_hash": "191554163171018329408793401449846957632",
"length": 2526.0
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c8ca21a2836993d7cb816668458e05e598574e55",
"target": {
"file": "fs/jfs/jfs_dmap.c",
"function": "dbAllocAG"
}
},
{
"id": "CVE-2025-38697-868f8778",
"signature_version": "v1",
"digest": {
"function_hash": "191554163171018329408793401449846957632",
"length": 2526.0
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1467a75819e41341cd5ebd16faa2af1ca3c8f4fe",
"target": {
"file": "fs/jfs/jfs_dmap.c",
"function": "dbAllocAG"
}
},
{
"id": "CVE-2025-38697-92e3261f",
"signature_version": "v1",
"digest": {
"function_hash": "191554163171018329408793401449846957632",
"length": 2526.0
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@30e19a884c0b11f33821aacda7e72e914bec26ef",
"target": {
"file": "fs/jfs/jfs_dmap.c",
"function": "dbAllocAG"
}
},
{
"id": "CVE-2025-38697-aa6090c5",
"signature_version": "v1",
"digest": {
"function_hash": "191554163171018329408793401449846957632",
"length": 2526.0
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2dd05f09cc323018136a7ecdb3d1007be9ede27f",
"target": {
"file": "fs/jfs/jfs_dmap.c",
"function": "dbAllocAG"
}
},
{
"id": "CVE-2025-38697-ad195971",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"309856049866342509725798327169682497116",
"24062441825334502293777560522776722753",
"198385365170970029598986200948761467815"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1467a75819e41341cd5ebd16faa2af1ca3c8f4fe",
"target": {
"file": "fs/jfs/jfs_dmap.c"
}
},
{
"id": "CVE-2025-38697-c93514fb",
"signature_version": "v1",
"digest": {
"function_hash": "191554163171018329408793401449846957632",
"length": 2526.0
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@173cfd741ad7073640bfb7e2344c2a0ee005e769",
"target": {
"file": "fs/jfs/jfs_dmap.c",
"function": "dbAllocAG"
}
},
{
"id": "CVE-2025-38697-e37a150e",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"309856049866342509725798327169682497116",
"24062441825334502293777560522776722753",
"198385365170970029598986200948761467815"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2dd05f09cc323018136a7ecdb3d1007be9ede27f",
"target": {
"file": "fs/jfs/jfs_dmap.c"
}
}
]