Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-39735

22
FAUCET Score

CVE-2025-39735 is a slab-out-of-bounds read vulnerability in the JFS filesystem's ea_get() function within the Linux kernel. This flaw occurs due to an integer overflow when clamping the extended attribute size, leading to a negative value being passed to print_hex_dump(). The corrupted length causes an extensive loop and subsequent out-of-bounds read in hex_dump_to_buffer(). The vulnerability is rated 7.1 HIGH (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H), indicating it can be exploited locally with low complexity by a low-privileged user, potentially leading to high confidentiality impact and high availability impact. The FAUCET Risk Score is 66/100, and the CWE is CWE-125. There is currently no evidence of active exploitation, nor are there known public exploits in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting low public awareness and attention for this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.19.325, < 4.20CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.4.287, < 5.4.292CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.10.231, < 5.10.236CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.15.174, < 5.15.180CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.1.120, < 6.1.134CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 49th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

autodeskpatch availablevia llm_extracted
View patch
freepbxpatch availablevia llm_extracted
View patch
honeywellpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: 19705-17086Fixed in: 5.15.180.1-1
microsoftpatch availablevia msrc
Product: 17099-17086Fixed in: 5.15.180.1-1
microsoftpatch availablevia msrc
Product: 19734-17084Fixed in: 6.6.92.2-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.85.1-4 on Azure Linux 3.0Fixed in: 6.6.92.2-1
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.176.3-3 on CBL Mariner 2.0Fixed in: 5.15.180.1-1
grafanavendor investigatingvia llm_extracted
View patch

Vendor Advisories (6)

grafanallm-grafana-3bfe68bd8f94bc6dCRITICAL

HP ThinPro 8.1 SP9 Security Updates

Feb 2, 2026
honeywellllm-honeywell-c82b5cfda9df97a3CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
autodeskllm-autodesk-c365b674a2ff5a3aCRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
freepbxllm-freepbx-e54908c7967265f6CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
redhatCVE-2025-39735Moderate

kernel: jfs: fix slab-out-of-bounds read in ea_get()

Apr 18, 2025
microsoft2025-Apr/CVE-2025-39735Important

jfs: fix slab-out-of-bounds read in ea_get()

Apr 8, 2025

References

git.kernel.org / stable/c/0beddc2a3f9b9cf7d8887973041e36c2d0fa3652
Patch
git.kernel.org / stable/c/16d3d36436492aa248b2d8045e75585ebcc2f34d
Patch
git.kernel.org / stable/c/3d6fd5b9c6acbc005e53d0211c7381f566babec1
Patch
git.kernel.org / stable/c/46e2c031aa59ea65128991cbca474bd5c0c2ecdb
Patch
git.kernel.org / stable/c/50afcee7011155933d8d5e8832f52eeee018cfd3
Patch
git.kernel.org / stable/c/5263822558a8a7c0d0248d5679c2dcf4d5cda61f
Patch
git.kernel.org / stable/c/78c9cbde8880ec02d864c166bcb4fe989ce1d95f
Patch
git.kernel.org / stable/c/a8c31808925b11393a6601f534bb63bac5366bab
Patch
git.kernel.org / stable/c/fdf480da5837c23b146c4743c18de97202fcab37
Patch
lists.debian.org / debian-lts-announce/2025/05/msg00030.html
lists.debian.org / debian-lts-announce/2025/05/msg00045.html