{
  "schema_version": "1.6.1",
  "id": "RPI-CVE-2025-39735",
  "modified": "2026-10-07T17:22:01Z",
  "upstream": [
    "CVE-2025-39735"
  ],
  "published": "2025-04-18T07:03:05Z",
  "summary": "jfs: fix slab-out-of-bounds read in ea_get()",
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix slab-out-of-bounds read in ea_get()\n\nDuring the \"size_check\" label in ea_get(), the code checks if the extended\nattribute list (xattr) size matches ea_size. If not, it logs\n\"ea_get: invalid extended attribute\" and calls print_hex_dump().\n\nHere, EALIST_SIZE(ea_buf->xattr) returns 4110417968, which exceeds\nINT_MAX (2,147,483,647). Then ea_size is clamped:\n\n\tint size = clamp_t(int, ea_size, 0, EALIST_SIZE(ea_buf->xattr));\n\nAlthough clamp_t aims to bound ea_size between 0 and 4110417968, the upper\nlimit is treated as an int, causing an overflow above 2^31 - 1. This leads\n\"size\" to wrap around and become negative (-184549328).\n\nThe \"size\" is then passed to print_hex_dump() (called \"len\" in\nprint_hex_dump()), it is passed as type size_t (an unsigned\ntype), this is then stored inside a variable called\n\"int remaining\", which is then assigned to \"int linelen\" which\nis then passed to hex_dump_to_buffer(). In print_hex_dump()\nthe for loop, iterates through 0 to len-1, where len is\n18446744073525002176, calling hex_dump_to_buffer()\non each iteration:\n\n\tfor (i = 0; i < len; i += rowsize) {\n\t\tlinelen = min(remaining, rowsize);\n\t\tremaining -= rowsize;\n\n\t\thex_dump_to_buffer(ptr + i, linelen, rowsize, groupsize,\n\t\t\t\t   linebuf, sizeof(linebuf), ascii);\n\n\t\t...\n\t}\n\nThe expected stopping condition (i < len) is effectively broken\nsince len is corrupted and very large. This eventually leads to\nthe \"ptr+i\" being passed to hex_dump_to_buffer() to get closer\nto the end of the actual bounds of \"ptr\", eventually an out of\nbounds access is done in hex_dump_to_buffer() in the following\nfor loop:\n\n\tfor (j = 0; j < len; j++) {\n\t\t\tif (linebuflen < lx + 2)\n\t\t\t\tgoto overflow2;\n\t\t\tch = ptr[j];\n\t\t...\n\t}\n\nTo fix this we should validate \"EALIST_SIZE(ea_buf->xattr)\"\nbefore it is utilised.",
  "affected": [
    {
      "package": {
        "ecosystem": "Raspberry Pi OS:12",
        "name": "linux"
      },
      "versions": [
        "1:6.6.74-1+rpt1",
        "1:6.12.20-1+rpt1~bpo12+1"
      ],
      "ecosystem_specific": {
        "binaries": [
          {
            "binary_name": "linux-image-6.6.74+rpt-rpi-2712",
            "binary_version": "1:6.6.74-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.74+rpt-rpi-v6",
            "binary_version": "1:6.6.74-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.74+rpt-rpi-v7",
            "binary_version": "1:6.6.74-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.74+rpt-rpi-v7l",
            "binary_version": "1:6.6.74-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.74+rpt-rpi-v8",
            "binary_version": "1:6.6.74-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.20+rpt-rpi-2712",
            "binary_version": "1:6.12.20-1+rpt1~bpo12+1"
          },
          {
            "binary_name": "linux-image-6.12.20+rpt-rpi-v6",
            "binary_version": "1:6.12.20-1+rpt1~bpo12+1"
          },
          {
            "binary_name": "linux-image-6.12.20+rpt-rpi-v7",
            "binary_version": "1:6.12.20-1+rpt1~bpo12+1"
          },
          {
            "binary_name": "linux-image-6.12.20+rpt-rpi-v7l",
            "binary_version": "1:6.12.20-1+rpt1~bpo12+1"
          },
          {
            "binary_name": "linux-image-6.12.20+rpt-rpi-v8",
            "binary_version": "1:6.12.20-1+rpt1~bpo12+1"
          }
        ]
      },
      "database_specific": {
        "per_version": {
          "1:6.6.74-1+rpt1": {
            "linux_commit": "a18d9ced4965462cb7b3b4252ada440395105308",
            "upstream_version": "6.6.74",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.6.87"
          },
          "1:6.12.20-1+rpt1~bpo12+1": {
            "linux_commit": "cd231d4775b14f228606c09f219b48308f6ab3aa",
            "upstream_version": "6.12.20",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.12.23"
          }
        }
      }
    },
    {
      "package": {
        "ecosystem": "Raspberry Pi OS:13",
        "name": "linux"
      },
      "versions": [
        "1:6.12.19-1+rpt1~bpo12+1",
        "1:6.12.19-1+rpt1",
        "1:6.12.20-1+rpt1"
      ],
      "ecosystem_specific": {
        "binaries": [
          {
            "binary_name": "linux-image-6.12.19+rpt-rpi-2712",
            "binary_version": "1:6.12.19-1+rpt1~bpo12+1"
          },
          {
            "binary_name": "linux-image-6.12.19+rpt-rpi-v6",
            "binary_version": "1:6.12.19-1+rpt1~bpo12+1"
          },
          {
            "binary_name": "linux-image-6.12.19+rpt-rpi-v7",
            "binary_version": "1:6.12.19-1+rpt1~bpo12+1"
          },
          {
            "binary_name": "linux-image-6.12.19+rpt-rpi-v7l",
            "binary_version": "1:6.12.19-1+rpt1~bpo12+1"
          },
          {
            "binary_name": "linux-image-6.12.19+rpt-rpi-v8",
            "binary_version": "1:6.12.19-1+rpt1~bpo12+1"
          },
          {
            "binary_name": "linux-image-6.12.19+rpt-rpi-2712",
            "binary_version": "1:6.12.19-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.19+rpt-rpi-v6",
            "binary_version": "1:6.12.19-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.19+rpt-rpi-v7",
            "binary_version": "1:6.12.19-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.19+rpt-rpi-v7l",
            "binary_version": "1:6.12.19-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.19+rpt-rpi-v8",
            "binary_version": "1:6.12.19-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.20+rpt-rpi-2712",
            "binary_version": "1:6.12.20-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.20+rpt-rpi-v6",
            "binary_version": "1:6.12.20-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.20+rpt-rpi-v7",
            "binary_version": "1:6.12.20-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.20+rpt-rpi-v7l",
            "binary_version": "1:6.12.20-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.20+rpt-rpi-v8",
            "binary_version": "1:6.12.20-1+rpt1"
          }
        ]
      },
      "database_specific": {
        "per_version": {
          "1:6.12.19-1+rpt1~bpo12+1": {
            "linux_commit": "121c2c384b9c2f4790ffb31b2cd25c7d75c8fda0",
            "upstream_version": "6.12.19",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.12.23"
          },
          "1:6.12.19-1+rpt1": {
            "linux_commit": "121c2c384b9c2f4790ffb31b2cd25c7d75c8fda0",
            "upstream_version": "6.12.19",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.12.23"
          },
          "1:6.12.20-1+rpt1": {
            "linux_commit": "cd231d4775b14f228606c09f219b48308f6ab3aa",
            "upstream_version": "6.12.20",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.12.23"
          }
        }
      }
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-39735"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/3d6fd5b9c6acbc005e53d0211c7381f566babec1"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/50afcee7011155933d8d5e8832f52eeee018cfd3"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/78c9cbde8880ec02d864c166bcb4fe989ce1d95f"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/46e2c031aa59ea65128991cbca474bd5c0c2ecdb"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/a8c31808925b11393a6601f534bb63bac5366bab"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/0beddc2a3f9b9cf7d8887973041e36c2d0fa3652"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/16d3d36436492aa248b2d8045e75585ebcc2f34d"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/5263822558a8a7c0d0248d5679c2dcf4d5cda61f"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/fdf480da5837c23b146c4743c18de97202fcab37"
    }
  ],
  "database_specific": {
    "source": "https://git.kernel.org/pub/scm/linux/security/vulns.git",
    "upstream_modified": "2026-08-05T12:19:11Z"
  }
}
