-

CVE-2025-38204

In the Linux kernel, the following vulnerability has been resolved:

jfs: fix array-index-out-of-bounds read in add_missing_indices

stbl is s8 but it must contain offsets into slot which can go from 0 to
127.

Added a bound check for that error and return -EIO if the check fails.
Also make jfs_readdir return with error if add_missing_indices returns
with an error.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
Product Linux
Default Statusunaffected
Version < 81af4b34fd72d390d7f237c6a545cc6d09707956
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < bfa4655d28f338e68d345aed80d19be7999bbce2
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 44618bee303bed151ef3a525ff79fbd7689593b5
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < c8399564a58fb6ea2ff21a6fd278417943cb51a5
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 5dff41a86377563f7a2b968aae00d25b4ceb37c9
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
VendorLinux
Product Linux
Default Statusaffected
Version <= 5.4.*
Version 5.4.295
Status unaffected
Version <= 5.10.*
Version 5.10.239
Status unaffected
Version <= 5.15.*
Version 5.15.186
Status unaffected
Version <= 6.15.*
Version 6.15.4
Status unaffected
Version <= *
Version 6.16
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.059
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string