CVE-2025-40080 - CVE House
Back to Database
Status published Unknown CVE-2025-40080

nbd: restrict sockets to TCP and UDP

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: nbd: restrict sockets to TCP and UDP Recently, syzbot started to abuse NBD with all kinds of sockets. Commit cf1b2326b734 ("nbd: verify socket is supported during setup") made sure the socket supported a shutdown() method. Explicitely accept TCP and UNIX stream sockets.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-40080

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Linux
Vulnerable Versions:
cf1b2326b734896734c6e167e41766f9cee7686a, 4df728651b8a99693c69962d8e5a5b9e5a3bbcc7, 083322455c67d278c56a66b73f1221f004ee600a, 4fa1cbd587ef967812f9d9f6ce46ec1dead7502c, 4.14.152, 4.19.82, 5.3.9, 5.4, 0, 6.1.156, 6.6.112, 6.12.53, 6.17.3, 6.18

Timeline

Official Publish: October 28th, 2025
Last Modified: July 14th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.