Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-38697

26
FAUCET Score

CVE-2025-38697 is a high-severity vulnerability in the Linux kernel's JFS filesystem, specifically affecting Debian and Linux kernel versions. It stems from an unchecked tree index in the dbAllocAG function, which could lead to out-of-bounds access if filesystem metadata is corrupted. With a CVSS score of 7.8, this local vulnerability (AV:L) allows an attacker with low privileges (PR:L) to achieve high confidentiality, integrity, and availability impacts (C:H/I:H/A:H). There is currently no known active exploitation, nor are there public Metasploit, Nuclei, or ExploitDB modules available, though it has garnered some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.12.1, < 5.4.297CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.241CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.190CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.149CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.6.103CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
6.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0017 is in the 27th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

ubuntupatch availablevia ubuntu_usn
Product: linux-xilinx (noble)Fixed in: 6.8.0-1023.24
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm-6.8 (jammy)Fixed in: 6.8.0-1044.44~22.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm (noble)Fixed in: 6.8.0-1044.44
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-fips (noble)Fixed in: 6.8.0-1046.52+fips1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure (noble)Fixed in: 6.8.0-1046.52
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-6.8 (jammy)Fixed in: 6.8.0-1051.57~22.04.1

Vendor Advisories (7)

ubuntuUSN-8126-1

Linux kernel (Azure) vulnerabilities

Mar 25, 2026
ubuntuUSN-8074-2

Linux kernel (Azure FIPS) vulnerabilities

Mar 4, 2026
ubuntuUSN-8074-1

Linux kernel (Azure) vulnerabilities

Mar 4, 2026
ubuntuUSN-8052-2

Linux kernel (Xilinx) vulnerabilities

Feb 24, 2026
ubuntuUSN-8028-8

Linux kernel (IBM) vulnerabilities

Feb 24, 2026
microsoft2025-Sep/CVE-2025-38697Important

jfs: upper bound check of tree index in dbAllocAG

Sep 9, 2025
redhatCVE-2025-38697Moderate

kernel: jfs: upper bound check of tree index in dbAllocAG

Sep 4, 2025

References

cert-portal.siemens.com / productcert/html/ssa-032379.html
git.kernel.org / stable/c/1467a75819e41341cd5ebd16faa2af1ca3c8f4fe
Patch
git.kernel.org / stable/c/173cfd741ad7073640bfb7e2344c2a0ee005e769
Patch
git.kernel.org / stable/c/2dd05f09cc323018136a7ecdb3d1007be9ede27f
Patch
git.kernel.org / stable/c/30e19a884c0b11f33821aacda7e72e914bec26ef
Patch
git.kernel.org / stable/c/49ea46d9025aa1914b24ea957636cbe4367a7311
Patch
git.kernel.org / stable/c/5bdb9553fb134fd52ec208a8b378120670f6e784
Patch
git.kernel.org / stable/c/a4f199203f79ca9cd7355799ccb26800174ff093
Patch
git.kernel.org / stable/c/c214006856ff52a8ff17ed8da52d50601d54f9ce
Patch
git.kernel.org / stable/c/c8ca21a2836993d7cb816668458e05e598574e55
Patch
lists.debian.org / debian-lts-announce/2025/10/msg00007.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2025/10/msg00008.html
Mailing ListThird Party Advisory