nbd: restrict sockets to TCP and UDP
Summary
| CVE | CVE-2025-40080 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-10-28 12:15:42 UTC |
| Updated | 2026-07-14 13:17:52 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: nbd: restrict sockets to TCP and UDP Recently, syzbot started to abuse NBD with all kinds of sockets. Commit cf1b2326b734 ("nbd: verify socket is supported during setup") made sure the socket supported a shutdown() method. Explicitely accept TCP and UNIX stream sockets. |
Risk And Classification
EPSS: 0.001830000 probability, percentile 0.080640000 (date 2026-07-14)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected cf1b2326b734896734c6e167e41766f9cee7686a c365e8f20f4201d873a70385bd919f0fb531e960 git | Not specified |
| CNA | Linux | Linux | affected cf1b2326b734896734c6e167e41766f9cee7686a 4f9e6ff6319dbcebea64b50af0304cf0ad7e97e7 git | Not specified |
| CNA | Linux | Linux | affected cf1b2326b734896734c6e167e41766f9cee7686a 37ad11f20e164c23ce827dd455b42c0fdd29685c git | Not specified |
| CNA | Linux | Linux | affected cf1b2326b734896734c6e167e41766f9cee7686a 808e2335bc1cf2293b9e36ccc94c267c81509c71 git | Not specified |
| CNA | Linux | Linux | affected cf1b2326b734896734c6e167e41766f9cee7686a 9f7c02e031570e8291a63162c6c046dc15ff85b0 git | Not specified |
| CNA | Linux | Linux | affected 4df728651b8a99693c69962d8e5a5b9e5a3bbcc7 git | Not specified |
| CNA | Linux | Linux | affected 083322455c67d278c56a66b73f1221f004ee600a git | Not specified |
| CNA | Linux | Linux | affected 4fa1cbd587ef967812f9d9f6ce46ec1dead7502c git | Not specified |
| CNA | Linux | Linux | affected 4.14.152 4.15 semver | Not specified |
| CNA | Linux | Linux | affected 4.19.82 4.20 semver | Not specified |
| CNA | Linux | Linux | affected 5.3.9 5.4 semver | Not specified |
| CNA | Linux | Linux | affected 5.4 | Not specified |
| CNA | Linux | Linux | unaffected 5.4 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.156 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.112 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.53 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.17.3 6.17.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18 * original_commit_for_fix | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
| ADP | Siemens | SIPLUS S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/4f9e6ff6319dbcebea64b50af0304cf0ad7e97e7 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/808e2335bc1cf2293b9e36ccc94c267c81509c71 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/9f7c02e031570e8291a63162c6c046dc15ff85b0 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| cert-portal.siemens.com/productcert/html/ssa-019113.html | 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e | cert-portal.siemens.com | |
| git.kernel.org/stable/c/c365e8f20f4201d873a70385bd919f0fb531e960 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/37ad11f20e164c23ce827dd455b42c0fdd29685c | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.