Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2025-37947

Description

In the Linux kernel, the following vulnerability has been resolved:ksmbd: prevent out-of-bounds stream writes by validating *posksmbd_vfs_stream_write() did not validate whether the write offset(*pos) was within the bounds of the existing stream data length (v_len).If *pos was greater than or equal to v_len, this could lead to anout-of-bounds memory write.This patch adds a check to ensure *pos is less than v_len beforeproceeding. If the condition fails, -EINVAL is returned.

POC

Reference

No PoCs from references.

Github

- https://github.com/w4zu/Debian_security