-

CVE-2025-38697

In the Linux kernel, the following vulnerability has been resolved:

jfs: upper bound check of tree index in dbAllocAG

When computing the tree index in dbAllocAG, we never check if we are
out of bounds realative to the size of the stree.
This could happen in a scenario where the filesystem metadata are
corrupted.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
Product Linux
Default Statusunaffected
Version < 5bdb9553fb134fd52ec208a8b378120670f6e784
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < a4f199203f79ca9cd7355799ccb26800174ff093
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 1467a75819e41341cd5ebd16faa2af1ca3c8f4fe
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 49ea46d9025aa1914b24ea957636cbe4367a7311
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 173cfd741ad7073640bfb7e2344c2a0ee005e769
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < c8ca21a2836993d7cb816668458e05e598574e55
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 2dd05f09cc323018136a7ecdb3d1007be9ede27f
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 30e19a884c0b11f33821aacda7e72e914bec26ef
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < c214006856ff52a8ff17ed8da52d50601d54f9ce
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
VendorLinux
Product Linux
Default Statusaffected
Version <= 5.4.*
Version 5.4.297
Status unaffected
Version <= 5.10.*
Version 5.10.241
Status unaffected
Version <= 5.15.*
Version 5.15.190
Status unaffected
Version <= 6.1.*
Version 6.1.149
Status unaffected
Version <= 6.6.*
Version 6.6.103
Status unaffected
Version <= 6.12.*
Version 6.12.43
Status unaffected
Version <= 6.15.*
Version 6.15.11
Status unaffected
Version <= 6.16.*
Version 6.16.2
Status unaffected
Version <= *
Version 6.17-rc1
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.143
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string