Security researchers have released a PoC for a high-severity vulnerability in the Linux kernel's ksmbd module, demonstrating a reliable way to allow local privilege escalation. The vulnerability, tracked as CVE-2025-37947, is an out-of-bounds write that can be exploited by an authenticated local attacker to gain full root control on a vulnerable system.
See also: Linux malware Koske hides in images of panda bears

This discovery, detailed by researchers at Doyensec, is the result of extensive research into vulnerabilities in the Server Message Block (SMB) , which has seen increased adoption in recent Linux releases. The public release of the exploit code highlights the practical risk this flaw poses to systems running the affected kernel module.
The root of CVE-2025-37947 lies in the ksmbd_vfs_stream_write(), which is responsible for handling write operations on file streams using extended attributes. The vulnerability can be triggered by an authenticated user on systems where ksmbd is configured with a writable share and the streams_xattr VFS module is enabled.
The flaw results from improper size validation when a user-supplied location and number of data exceed the XATTR_SIZE_MAX of 65,536 bytes. Although the code truncates the allocation size for the buffer, it fails to adjust the number for the memcpy accordingly. This logic error allows an attacker to write a controlled amount of data beyond the kernel's allocated buffer limit, leading to memory corruption in a contiguous memory region.
See also: CISA added Linux kernel vulnerability to KEV List

Doyensec researchers described how this out-of-bounds write can be escalated to a full root exploit on a modern Linux system, specifically Ubuntu 22.04.5 LTS. The exploitation strategy involves a sophisticated, multi-layered process that begins with heap configuration to manipulate the kernel's memory layout.
By carefully allocating and freeing kernel objects, attackers could place a controlled victim object, a kernel message structure msg_msg, just after the vulnerable buffer. The out-of-bounds write is then used to corrupt the msg_msg header, creating a use-after-free (UAF) condition. This UAF primitive is then used to leak kernel memory addresses by bypassing Kernel Address Space Randomization (KASLR). With KASLR bypassed, attackers reuse the UAF to replace a function pointer in a pipe_buffer, hijacking the kernel's control flow to execute a ROP chain that grants them root privileges.
In their disclosure, the researchers published the full local privilege escalation exploit on GitHub. This allows other security professionals to analyze the attack and assess its impact on their systems. While the current exploit focuses on local access, the researchers noted that remote exploitation is significantly more difficult, as it would likely require a separate information disclosure vulnerability to bypass KASLR and make the heap configuration trustworthy.
See also: CISA added Linux kernel vulnerability to KEV List

This finding is part of a broader security audit of ksmbd by Doyensec, which has previously uncovered other critical vulnerabilities, including multiple unauthenticated race conditions and memory exhaustion flaws. System administrators are advised to reconsider their use of ksmbd and ensure their systems are updated against CVE-2025-37947 as updates become available from their Linux distribution providers.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
