CVE-2025-39735 is a slab-out-of-bounds read vulnerability in the JFS filesystem's ea_get() function within the Linux kernel. This flaw occurs due to an integer overflow when clamping the extended attribute size, leading to a negative value being passed to print_hex_dump(). The corrupted length causes an extensive loop and subsequent out-of-bounds read in hex_dump_to_buffer(). The vulnerability is rated 7.1 HIGH (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H), indicating it can be exploited locally with low complexity by a low-privileged user, potentially leading to high confidentiality impact and high availability impact. The FAUCET Risk Score is 66/100, and the CWE is CWE-125. There is currently no evidence of active exploitation, nor are there known public exploits in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting low public awareness and attention for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.19.325, < 4.20CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.4.287, < 5.4.292CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.10.231, < 5.10.236CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.15.174, < 5.15.180CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.1.120, < 6.1.134CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP9 Security Updates
Feb 2, 2026HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025kernel: jfs: fix slab-out-of-bounds read in ea_get()
Apr 18, 2025jfs: fix slab-out-of-bounds read in ea_get()
Apr 8, 2025