CVE-2025-40080 — Improper Validation of Specified Type of Input in Linux
Severity
3.2LOWOSV
No vectorEPSS
0.0%
top 87.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 28
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
nbd: restrict sockets to TCP and UDP
Recently, syzbot started to abuse NBD with all kinds of sockets.
Commit cf1b2326b734 ("nbd: verify socket is supported during setup")
made sure the socket supported a shutdown() method.
Explicitely accept TCP and UNIX stream sockets.
Affected Packages7 packages
▶CVEListV5linux/linuxcf1b2326b734896734c6e167e41766f9cee7686a — c365e8f20f4201d873a70385bd919f0fb531e960+8