Vulnerability advisory / 2025

CVE-2025-37858: allocation-group arithmetic overflow in JFS

A JFS allocation-group size calculation needed a 64-bit operand before shifting on 32-bit architectures.

Overview

The public Linux CVE describes an integer-width problem in dbExtendFS(), in fs/jfs/jfs_dmap.c. JFS calculated an allocation-group size with the expression 1 << l2agsize. A large shift applied to the 32-bit operand could produce undefined behavior and an invalid group size.

The correction casts the left operand to s64 before shifting: (s64)1 << l2agsize. This makes the calculation use 64-bit arithmetic, matching the type of the stored allocation-group size. Casting only the result would leave the problematic operation at its original width.

Invalid allocation-group sizing can affect later filesystem operations. The public advisory describes potential filesystem corruption and kernel crashes. It also links the upstream correction and affected-version records; distribution-specific fixes should be checked against the package vendor’s advisory.

For code review, the wider lesson is to inspect the types of intermediate arithmetic operations, particularly shifts and size calculations. A wide destination variable does not itself make a narrower expression safe.

Key facts

Vulnerability advisory
2025
Public record
Linux kernel · National Vulnerability Database
Affected code
JFS filesystem · dbExtendFS() in fs/jfs/jfs_dmap.c
Topics
CVE-2025-37858 · JFS · Integer arithmetic · Intermediate types
Primary source

Related work

08Contact

Let’s solve the next hard problem.

Tell me what you’re building, what is at stake and when you need a result. I’ll discuss the fit and propose a defined scope, deliverables and price.