CVE-2025-71292 PUBLISHED

jfs: nlink overflow in jfs_rename

Assigner: Linux
Reserved: 06.05.2026 Published: 06.05.2026 Updated: 06.05.2026

In the Linux kernel, the following vulnerability has been resolved:

jfs: nlink overflow in jfs_rename

If nlink is maximal for a directory (-1) and inside that directory you perform a rename for some child directory (not moving from the parent), then the nlink of the first directory is first incremented and later decremented. Normally this is fine, but when nlink = -1 this causes a wrap around to 0, and then drop_nlink issues a warning.

After applying the patch syzbot no longer issues any warnings. I also ran some basic fs tests to look for any regressions.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 2108829a59f081e822fdab8c2cd7131deb8aa8a1 (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to b4330a0d0947fbdc9d445cbbeabd8cc910a8c9ca (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to a3d66089e50a6e0142f8884471f74292102ea9aa (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to f70fcbc2ac7c24f087a2c895c5753aa730b1e479 (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 5d77c36cd4b698649f5c30c5f6c084f4f61d1880 (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to fe136426e30ca6debcf916fd6a141555ed9fde74 (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 93c325746ae59709b4f9bad4e3e4761c8d566c70 (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 9218dc26fd922b09858ecd3666ed57dfd8098da8 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • unaffected from 5.10.252 to 5.10.* (incl.)
  • unaffected from 5.15.202 to 5.15.* (incl.)
  • unaffected from 6.1.165 to 6.1.* (incl.)
  • unaffected from 6.6.128 to 6.6.* (incl.)
  • unaffected from 6.12.75 to 6.12.* (incl.)
  • unaffected from 6.18.16 to 6.18.* (incl.)
  • unaffected from 6.19.6 to 6.19.* (incl.)
  • unaffected from 7.0 to * (incl.)

References