Linux Kernel JFS Inode Mode Verification Vulnerability

Vulnerability

A vulnerability exists in the Linux kernel's JFS (Journaled File System) implementation, where the inode mode retrieved from a corrupted disk may be invalid. This issue can lead to improper handling of file types, particularly special files. The vulnerability affects the stable branch of the Linux kernel.

Impact

The vulnerability can cause the file system to misinterpret inode data, potentially leading to incorrect file operations or system errors.

Reproduction

The vulnerability can be reproduced by loading a JFS file system from a corrupted disk that contains invalid inode modes. This can be done by creating a disk image with JFS data and deliberately corrupting the inode information, then mounting the image with the Linux kernel version that contains the vulnerability.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed. Instructions for upgrading the Linux kernel can be found in the official Linux documentation.

Added: Dec 8, 2025, 1:32 AM
Updated: Dec 8, 2025, 1:32 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
4.3
remediation
7.7
relevance
1.4
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.