CVE-2025-38204: Debian Linux

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: jfs: fix array-index-out-of-bounds read in add_missing_indices stbl is s8 but it must contain offsets into slot which can go from 0 to 127. Added a bound check for that error and return -EIO if the check fails. Also make jfs_readdir return with error if add_missing_indices returns with an error.

Affected products

  • Debian Debian Linux: version 11.0 only
  • Linux Linux Kernel: before 5.4.295 (fixed in 5.4.295); from 5.5, before 5.10.239 (fixed in 5.10.239); from 5.11, before 5.15.186 (fixed in 5.15.186); from 5.16, before 6.15.4 (fixed in 6.15.4)

Published 2025-07-04. Last modified 2026-07-30.