PT-2025-44139 · Linux+4 · Linux Kernel+4

Published

2025-08-27

·

Updated

2026-05-07

·

CVE-2025-40071

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw within the tty subsystem, specifically in the n gsm component. The issue arises from the potential to block the input queue while waiting for a Modem Status Command (MSC) response. This occurs when opening a Data Link Connection Identifier (DLC) channel, where gsm queue() processes incoming frames and gsm dlci open() calls gsm modem update(). In basic mode, gsm modem upd via msc() attempts to send an MSC without waiting for a response, potentially leading to a blockage of the input queue. The resolution involves defining a new function, gsm modem send initial msc(), to handle sending the MSC without blocking. This issue only affects basic encoding and does not impact advanced encoding or convergence layer type 2.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

AZL-68942
BDU:2025-16403
CVE-2025-40071
ECHO-C719-8FFC-A4C2
MGASA-2025-0309
MGASA-2025-0310
OESA-2025-2633
OESA-2025-2634
OESA-2025-2635
OPENSUSE-SU-2025:15702-1
OPENSUSE-SU-2025:20091-1
OPENSUSE-SU-2026:10301-1
SUSE-SU-2025:21040-1
SUSE-SU-2025:21052-1
SUSE-SU-2025:21056-1
SUSE-SU-2025:21064-1
SUSE-SU-2025:21080-1
SUSE-SU-2025:21147-1
SUSE-SU-2025:21180-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4128-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4140-1
SUSE-SU-2025:4141-1
SUSE-SU-2025:4301-1
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8048-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8165-1
USN-8261-1

Affected Products

Debian
Linuxmint
Linux Kernel
Suse
Ubuntu