Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Linux Linux — ksmbd: prevent out-of-bounds stream writes by validating *pos
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U H H H 7.8 .0051 41.4 —
AFFECTED
Product Versions Fixed
Linux 0626e6641f6b467447c81dd7678a69c66f7746cf – —
Linux 5.15 – 6.1.139
TIMELINE
Apr 16 Reserved by Linux
May 20 Published (CNA: Linux)
Jul 30 RESCORED — CVE-2025-37947 (Linux). CVSS 8.8 → 7.8 (NVD).
Aug 4 EXPLOIT PUBLISHED — CVE-2025-37947 (Linux). Public exploit reference added.
Description
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: prevent out-of-bounds stream writes by validating *pos
ksmbd_vfs_stream_write() did not validate whether the write offset
(*pos) was within the bounds of the existing stream data length (v_len).
If *pos was greater than or equal to v_len, this could lead to an
out-of-bounds memory write.
This patch adds a check to ensure *pos is less than v_len before
proceeding. If the condition fails, -EINVAL is returned.
Lifecycle
Complete event history — 4 events, chronological
| Date | Event | Detail |
| April 16, 2025 | Reserved | Reserved by Linux |
| May 20, 2025 | Published | Published (CNA: Linux) |
| July 30, 2026 | RESCORED | RESCORED — CVE-2025-37947 (Linux). CVSS 8.8 → 7.8 (NVD). |
| August 4, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2025-37947 (Linux). Public exploit reference added. |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Linux | Linux | — | 0626e6641f6b467447c81dd7678a69c66f7746cf | — |
| Linux | Linux | — | 5.15 | 6.1.139 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-37947 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.