CVE Database
/

CVE-2025-40080

Back to search

CVE-2025-40080

Published: Oct 28, 2025

Modified: May 23, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: nbd: restrict sockets to TCP and UDP Recently, syzbot started to abuse NBD with all kinds of sockets. Commit cf1b2326b734 ("nbd: verify socket is supported during setup") made sure the socket supported a shutdown() method. Explicitely accept TCP and UNIX stream sockets.

VendorProductVersions

Linux

Linux

affected
cf1b2326b734896734c6e167e41766f9cee7686a - < c365e8f20f4201d873a70385bd919f0fb531e960
affected
cf1b2326b734896734c6e167e41766f9cee7686a - < 4f9e6ff6319dbcebea64b50af0304cf0ad7e97e7
affected
cf1b2326b734896734c6e167e41766f9cee7686a - < 37ad11f20e164c23ce827dd455b42c0fdd29685c
affected
cf1b2326b734896734c6e167e41766f9cee7686a - < 808e2335bc1cf2293b9e36ccc94c267c81509c71
affected
cf1b2326b734896734c6e167e41766f9cee7686a - < 9f7c02e031570e8291a63162c6c046dc15ff85b0

+6 more versions

Linux

Linux

affected
5.4
unaffected
0 - < 5.4
unaffected
6.1.156 - <= 6.1.*
unaffected
6.6.112 - <= 6.6.*
unaffected
6.12.53 - <= 6.12.*

+2 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now