← לוח פגיעויות

CVE-2025-37947

גבוהה 7.8

תיאור (מקור, אנגלית)

In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds stream writes by validating *pos ksmbd_vfs_stream_write() did not validate whether the write offset (*pos) was within the bounds of the existing stream data length (v_len). If *pos was greater than or equal to v_len, this could lead to an out-of-bounds memory write. This patch adds a check to ensure *pos is less than v_len before proceeding. If the condition fails, -EINVAL is returned.

מדדים

CVSS 3.1
7.8 (HIGH) מקור הציון: NVD CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
1% (אחוזון 000) נכון ל-20/9/2026
CWE
CWE-787

מוצרים מושפעים

linux: linux kernel; debian: debian linux

קישורים