Answer in brief
CVE-2025-37956 records a Unknown severity vulnerability in ksmbd: prevent rename with empty string. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=0626e6641f6b467447c81dd7678a69c66f7746cf <6ee551672c8cf36108b0cfba92ec0c7c28ac3439 || >=0626e6641f6b467447c81dd7678a69c66f7746cf <c57301e332cc413fe0a7294a90725f4e21e9549d || >=0626e6641f6b467447c81dd7678a69c66f7746cf <d7f2c00acb1ef64304fd40ac507e9213ff1d9b5c || >=0626e6641f6b467447c81dd7678a69c66f7746cf <53e3e5babc0963a92d856a5ec0ce92c59f54bc12 | 6ee551672c8cf36108b0cfba92ec0c7c28ac3439, c57301e332cc413fe0a7294a90725f4e21e9549d, d7f2c00acb1ef64304fd40ac507e9213ff1d9b5c, 53e3e5babc0963a92d856a5ec0ce92c59f54bc12 |
| Linux/Linuxgeneric | 5.15 | Not reported |
Published upstream
May 20, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent rename with empty string Client can send empty newname string to ksmbd server. It will cause a kernel oops from d_alloc. This patch return the error when attempting to rename a file or directory with an empty new name string.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2025-37956 records a Unknown severity vulnerability in ksmbd: prevent rename with empty string. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=0626e6641f6b467447c81dd7678a69c66f7746cf <6ee551672c8cf36108b0cfba92ec0c7c28ac3439 || >=0626e6641f6b467447c81dd7678a69c66f7746cf <c57301e332cc413fe0a7294a90725f4e21e9549d || >=0626e6641f6b467447c81dd7678a69c66f7746cf <d7f2c00acb1ef64304fd40ac507e9213ff1d9b5c || >=0626e6641f6b467447c81dd7678a69c66f7746cf <53e3e5babc0963a92d856a5ec0ce92c59f54bc12 | 6ee551672c8cf36108b0cfba92ec0c7c28ac3439, c57301e332cc413fe0a7294a90725f4e21e9549d, d7f2c00acb1ef64304fd40ac507e9213ff1d9b5c, 53e3e5babc0963a92d856a5ec0ce92c59f54bc12 |
| Linux/Linuxgeneric | 5.15 | Not reported |
Published upstream
May 20, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent rename with empty string Client can send empty newname string to ksmbd server. It will cause a kernel oops from d_alloc. This patch return the error when attempting to rename a file or directory with an empty new name string.
Quoted source text, attributed separately from HOL analysis.