CVE-2025-40080
28.10.2025, 12:15
In the Linux kernel, the following vulnerability has been resolved:
nbd: restrict sockets to TCP and UDP
Recently, syzbot started to abuse NBD with all kinds of sockets.
Commit cf1b2326b734 ("nbd: verify socket is supported during setup")
made sure the socket supported a shutdown() method.
Explicitely accept TCP and UNIX stream sockets.EnginsightAwaiting analysis
This vulnerability is currently awaiting analysis.
Debian Releases
Vulnerability Media Exposure
References