CVE-2025-40080: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: nbd: restrict sockets to TCP and UDP Recently, syzbot started to abuse NBD with all kinds of sockets. Commit cf1b2326b734 ("nbd: verify socket is supported during setup") made sure the socket supported a shutdown() method. Explicitely accept TCP and UNIX stream sockets.

Affected products

  • Linux Linux: from 4.14.152, before 4.15 (fixed in 4.15); from 4.19.82, before 4.20 (fixed in 4.20); from 5.3.9, before 5.4 (fixed in 5.4); from 5.4, before 6.1.156 (fixed in 6.1.156); from 6.2, before 6.6.112 (fixed in 6.6.112); from 6.7, before 6.12.53 (fixed in 6.12.53); …
  • Siemens SIMATIC s7-1500 CPU 1518-4 Pn/dp Mfp: from V3.1.6
  • Siemens SIMATIC s7-1500 CPU 1518f-4 Pn/dp Mfp: from V3.1.6
  • Siemens Siplus s7-1500 CPU 1518-4 Pn/dp Mfp: from V3.1.6

Published 2025-10-28. Last modified 2026-07-14.