Answer in brief
CVE-2025-37947 records a Unknown severity vulnerability in ksmbd: prevent out-of-bounds stream writes by validating *pos. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-37947 records a Unknown severity vulnerability in ksmbd: prevent out-of-bounds stream writes by validating *pos. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=0626e6641f6b467447c81dd7678a69c66f7746cf <7f61da79df86fd140c7768e668ad846bfa7ec8e1 || >=0626e6641f6b467447c81dd7678a69c66f7746cf <04c8a38c60346bb5a7c49b276de7233f703ce9cb || >=0626e6641f6b467447c81dd7678a69c66f7746cf <d62ba16563a86aae052f96d270b3b6f78fca154c || >=0626e6641f6b467447c81dd7678a69c66f7746cf <e6356499fd216ed6343ae0363f4c9303f02c5034 || >=0626e6641f6b467447c81dd7678a69c66f7746cf <0ca6df4f40cf4c32487944aaf48319cb6c25accc | 7f61da79df86fd140c7768e668ad846bfa7ec8e1, 04c8a38c60346bb5a7c49b276de7233f703ce9cb, d62ba16563a86aae052f96d270b3b6f78fca154c, e6356499fd216ed6343ae0363f4c9303f02c5034, 0ca6df4f40cf4c32487944aaf48319cb6c25accc |
| Linux/Linuxgeneric | 5.15 | Not reported |
Published upstream
May 20, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds stream writes by validating *pos ksmbd_vfs_stream_write() did not validate whether the write offset (*pos) was within the bounds of the existing stream data length (v_len). If *pos was greater than or equal to v_len, this could lead to an out-of-bounds memory write. This patch adds a check to ensure *pos is less than v_len before proceeding. If the condition fails, -EINVAL is returned.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=0626e6641f6b467447c81dd7678a69c66f7746cf <7f61da79df86fd140c7768e668ad846bfa7ec8e1 || >=0626e6641f6b467447c81dd7678a69c66f7746cf <04c8a38c60346bb5a7c49b276de7233f703ce9cb || >=0626e6641f6b467447c81dd7678a69c66f7746cf <d62ba16563a86aae052f96d270b3b6f78fca154c || >=0626e6641f6b467447c81dd7678a69c66f7746cf <e6356499fd216ed6343ae0363f4c9303f02c5034 || >=0626e6641f6b467447c81dd7678a69c66f7746cf <0ca6df4f40cf4c32487944aaf48319cb6c25accc | 7f61da79df86fd140c7768e668ad846bfa7ec8e1, 04c8a38c60346bb5a7c49b276de7233f703ce9cb, d62ba16563a86aae052f96d270b3b6f78fca154c, e6356499fd216ed6343ae0363f4c9303f02c5034, 0ca6df4f40cf4c32487944aaf48319cb6c25accc |
| Linux/Linuxgeneric | 5.15 | Not reported |
Published upstream
May 20, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds stream writes by validating *pos ksmbd_vfs_stream_write() did not validate whether the write offset (*pos) was within the bounds of the existing stream data length (v_len). If *pos was greater than or equal to v_len, this could lead to an out-of-bounds memory write. This patch adds a check to ensure *pos is less than v_len before proceeding. If the condition fails, -EINVAL is returned.
Quoted source text, attributed separately from HOL analysis.