CVE-2025-71292
Description
In the Linux kernel, the following vulnerability has been resolved: jfs: nlink overflow in jfs_rename If nlink is maximal for a directory (-1) and inside that directory you perform a rename for some child directory (not moving from the parent), then the nlink of the first directory is first incremented and later decremented. Normally this is fine, but when nlink = -1 this causes a wrap around to 0, and then drop_nlink issues a warning. After applying the patch syzbot no longer issues any warnings. I also ran some basic fs tests to look for any regressions.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
Linux kernel Affected 2 releases
| Version | Status | Fixed in |
|---|---|---|
| 2.6.12 | Affected | โ |
| โ | Affected | 5.10.252 |
SUSE Affected 1 release
| Version | Status | Fixed in |
|---|---|---|
| โ | Affected | โ |
Debian Fixed 5 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Fixed | 6.12.85-1 |
| sid | Fixed | 6.19.6-1 |
| forky | Fixed | 6.19.6-1 |
| bullseye | Fixed | 5.10.257-1 |
| bookworm | Fixed | 6.1.170-1 |
References
- https://git.kernel.org/stable/c/2108829a59f081e822fdab8c2cd7131deb8aa8a1
- https://git.kernel.org/stable/c/5d77c36cd4b698649f5c30c5f6c084f4f61d1880
- https://git.kernel.org/stable/c/9218dc26fd922b09858ecd3666ed57dfd8098da8
- https://git.kernel.org/stable/c/93c325746ae59709b4f9bad4e3e4761c8d566c70
- https://git.kernel.org/stable/c/a3d66089e50a6e0142f8884471f74292102ea9aa
- https://git.kernel.org/stable/c/b4330a0d0947fbdc9d445cbbeabd8cc910a8c9ca
- https://git.kernel.org/stable/c/f70fcbc2ac7c24f087a2c895c5753aa730b1e479
- https://git.kernel.org/stable/c/fe136426e30ca6debcf916fd6a141555ed9fde74
- https://www.suse.com/security/cve/CVE-2025-71292.html
- https://security-tracker.debian.org/tracker/CVE-2025-71292
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.