Home

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent rename with empty string Client can send empty newname string to ksmbd server. It will cause a kernel oops from d_alloc. This patch return the error when attempting to rename a file or directory with an empty new name string.

PUBLISHED Reserved 2025-04-16 | Published 2025-05-20 | Updated 2026-05-11 | Assigner Linux

Product status

Default status
unaffected

0626e6641f6b467447c81dd7678a69c66f7746cf (git) before 6ee551672c8cf36108b0cfba92ec0c7c28ac3439
affected

0626e6641f6b467447c81dd7678a69c66f7746cf (git) before c57301e332cc413fe0a7294a90725f4e21e9549d
affected

0626e6641f6b467447c81dd7678a69c66f7746cf (git) before d7f2c00acb1ef64304fd40ac507e9213ff1d9b5c
affected

0626e6641f6b467447c81dd7678a69c66f7746cf (git) before 53e3e5babc0963a92d856a5ec0ce92c59f54bc12
affected

Default status
affected

5.15
affected

Any version before 5.15
unaffected

6.6.91 (semver)
unaffected

6.12.29 (semver)
unaffected

6.14.7 (semver)
unaffected

6.15 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/6ee551672c8cf36108b0cfba92ec0c7c28ac3439

git.kernel.org/...c/c57301e332cc413fe0a7294a90725f4e21e9549d

git.kernel.org/...c/d7f2c00acb1ef64304fd40ac507e9213ff1d9b5c

git.kernel.org/...c/53e3e5babc0963a92d856a5ec0ce92c59f54bc12

cve.org (CVE-2025-37956)

nvd.nist.gov (CVE-2025-37956)

Download JSON