Back to search
CVE-2025-40080
Published: Oct 28, 2025
Modified: May 23, 2026
PUBLISHED
Description
In the Linux kernel, the following vulnerability has been resolved: nbd: restrict sockets to TCP and UDP Recently, syzbot started to abuse NBD with all kinds of sockets. Commit cf1b2326b734 ("nbd: verify socket is supported during setup") made sure the socket supported a shutdown() method. Explicitely accept TCP and UNIX stream sockets.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected cf1b2326b734896734c6e167e41766f9cee7686a - < c365e8f20f4201d873a70385bd919f0fb531e960affected cf1b2326b734896734c6e167e41766f9cee7686a - < 4f9e6ff6319dbcebea64b50af0304cf0ad7e97e7affected cf1b2326b734896734c6e167e41766f9cee7686a - < 37ad11f20e164c23ce827dd455b42c0fdd29685caffected cf1b2326b734896734c6e167e41766f9cee7686a - < 808e2335bc1cf2293b9e36ccc94c267c81509c71affected cf1b2326b734896734c6e167e41766f9cee7686a - < 9f7c02e031570e8291a63162c6c046dc15ff85b0+6 more versions |
Linux | Linux | affected 5.4unaffected 0 - < 5.4unaffected 6.1.156 - <= 6.1.*unaffected 6.6.112 - <= 6.6.*unaffected 6.12.53 - <= 6.12.*+2 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now