CVE-2025-37925
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2025-37925 is a Linux kernel vulnerability related to the JFS file system. The issue was identified by Syzbot, who reported a kernel bug occurring when 'clear_inode()' attempts to finalize an inode of an unsupported type. Specifically, inode types between 5 and 15, which are reserved for future extensions according to JFS layout description, should not be encountered on valid filesystems. This vulnerability, if exploited, could lead to an invalid opcode error and potentially allow unintended code execution. A fix for this issue involves adding an extra check for valid inode types in 'copy_from_dinode()'.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.