PT-2025-44148 · Linux+4 · Linux Kernel+4

Published

2025-09-09

·

Updated

2026-05-07

·

CVE-2025-40080

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel had a flaw in the Network Block Device (NBD) module where it permitted the use of various socket types, leading to potential abuse. Specifically, a testing tool named syzbot exploited NBD using unsupported socket types. A previous commit aimed to ensure sockets supported a shutdown method, but did not fully restrict the allowed socket types. The issue was addressed by explicitly accepting only TCP and UNIX stream sockets.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

AZL-68879
BDU:2025-16407
CVE-2025-40080
DLA-4379-1
DSA-6053-1
ECHO-6F9C-84C6-7116
MGASA-2025-0309
MGASA-2025-0310
OESA-2025-2656
OESA-2025-2657
OESA-2025-2658
OPENSUSE-SU-2025:15702-1
OPENSUSE-SU-2025:20091-1
OPENSUSE-SU-2026:10301-1
SUSE-SU-2025:21040-1
SUSE-SU-2025:21052-1
SUSE-SU-2025:21056-1
SUSE-SU-2025:21064-1
SUSE-SU-2025:21080-1
SUSE-SU-2025:21147-1
SUSE-SU-2025:21180-1
SUSE-SU-2025:4128-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4140-1
SUSE-SU-2025:4301-1
SUSE-SU-2025:4393-1
SUSE-SU-2025:4516-1
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8048-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8165-1
USN-8261-1

Affected Products

Debian
Linuxmint
Linux Kernel
Suse
Ubuntu