cbcvebase.
CVE-2025-40080
published 2025-10-28

CVE-2025-40080: In the Linux kernel, the following vulnerability has been resolved: nbd: restrict sockets to TCP and UDP Recently, syzbot started to abuse NBD with all kinds…

PriorityP419high7.8
EPSS
0.19%
9.2th percentile
In the Linux kernel, the following vulnerability has been resolved: nbd: restrict sockets to TCP and UDP Recently, syzbot started to abuse NBD with all kinds of sockets. Commit cf1b2326b734 ("nbd: verify socket is supported during setup") made sure the socket supported a shutdown() method. Explicitely accept TCP and UNIX stream sockets.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.14.152 < 4.154.15
linuxlinux>= 4.19.82 < 4.204.20
linuxlinux>= 5.3.9 < 5.45.4
linuxlinux>= cf1b2326b734896734c6e167e41766f9cee7686a < c365e8f20f4201d873a70385bd919f0fb531e960c365e8f20f4201d873a70385bd919f0fb531e960
linuxlinux>= cf1b2326b734896734c6e167e41766f9cee7686a < 4f9e6ff6319dbcebea64b50af0304cf0ad7e97e74f9e6ff6319dbcebea64b50af0304cf0ad7e97e7
linuxlinux>= cf1b2326b734896734c6e167e41766f9cee7686a < 37ad11f20e164c23ce827dd455b42c0fdd29685c37ad11f20e164c23ce827dd455b42c0fdd29685c
linuxlinux>= cf1b2326b734896734c6e167e41766f9cee7686a < 808e2335bc1cf2293b9e36ccc94c267c81509c71808e2335bc1cf2293b9e36ccc94c267c81509c71
linuxlinux>= cf1b2326b734896734c6e167e41766f9cee7686a < 9f7c02e031570e8291a63162c6c046dc15ff85b09f7c02e031570e8291a63162c6c046dc15ff85b0
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 5.4.0 < 6.1.1566.1.156
linuxlinux_kernel>= 6.13.0 < 6.17.36.17.3
linuxlinux_kernel>= 6.2.0 < 6.6.1126.6.112
linuxlinux_kernel>= 6.7.0 < 6.12.536.12.53
msrcazl3_kernel_6.6.104.2-4_on_azure_linux_3.0
ubuntulinux-aws

CVSS provenance

vendor_ubuntu7.8HIGH
osv3.2LOW
vendor_redhat6.1MEDIUM
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.