CVE-2025-37947: Debian Linux

High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds stream writes by validating *pos ksmbd_vfs_stream_write() did not validate whether the write offset (*pos) was within the bounds of the existing stream data length (v_len). If *pos was greater than or equal to v_len, this could lead to an out-of-bounds memory write. This patch adds a check to ensure *pos is less than v_len before proceeding. If the condition fails, -EINVAL is returned.

Affected products

  • Debian Debian Linux: version 11.0 only
  • Linux Linux Kernel: from 5.15, before 6.1.139 (fixed in 6.1.139); from 6.2, before 6.6.91 (fixed in 6.6.91); from 6.7, before 6.12.29 (fixed in 6.12.29); from 6.13, before 6.14.7 (fixed in 6.14.7); version 6.15 only

Published 2025-05-20. Last modified 2026-07-30.