Wind River Support Network

HomeDefectsLIN1023-15409
Acknowledged

LIN1023-15409 : Security Advisory - linux - CVE-2025-39842

Created: Sep 21, 2025    Updated: Sep 24, 2025
Found In Version: 10.23.30.1
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:[EOL][EOL]ocfs2: prevent release journal inode after journal shutdown[EOL][EOL]Before calling ocfs2_delete_osb(), ocfs2_journal_shutdown() has already[EOL]been executed in ocfs2_dismount_volume(), so osb->journal must be NULL. [EOL]Therefore, the following calltrace will inevitably fail when it reaches[EOL]jbd2_journal_release_jbd_inode().[EOL][EOL]ocfs2_dismount_volume()->[EOL]  ocfs2_delete_osb()->[EOL]    ocfs2_free_slot_info()->[EOL]      __ocfs2_free_slot_info()->[EOL]        evict()->[EOL]          ocfs2_evict_inode()->[EOL]            ocfs2_clear_inode()->[EOL]\t      jbd2_journal_release_jbd_inode(osb->journal->j_journal,[EOL][EOL]Adding osb->journal checks will prevent null-ptr-deref during the above[EOL]execution path.
Live chat
Online