NONE · 0

CVE-2025-40080

In the Linux kernel, the following vulnerability has been resolved: nbd: restrict sockets to TCP and UDP Recently, syzbot started to abuse NBD with all kinds of sockets. Commit cf1b2326b734 ("nbd: ...

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: nbd: restrict sockets to TCP and UDP Recently, syzbot started to abuse NBD with all kinds of sockets. Commit cf1b2326b734 ("nbd: verify socket is supported during setup") made sure the socket supported a shutdown() method. Explicitely accept TCP and UNIX stream sockets.

References

FAQ

What is CVE-2025-40080?

CVE-2025-40080 is a documented vulnerability. In the Linux kernel, the following vulnerability has been resolved: nbd: restrict sockets to TCP and UDP Recently, syzbot started to abuse NBD with all kinds of sockets. Commit cf1b2326b734 ("nbd: ...

How severe is CVE-2025-40080?

CVSS scoring is not yet available for CVE-2025-40080. Check NVD for updates.

Is there a patch for CVE-2025-40080?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.