CVE-2025-40231 addresses a lock inversion deadlock in the Linux kernel's vsock subsystem, specifically within the vsock_assign_transport() function. This vulnerability, introduced by a prior commit, arises when vsock_linger() is called, creating a circular dependency between vsock_register_mutex and sk_lock-AF_VSOCK. While no CVSS score is provided, the FAUCET Risk Score of 7/100 suggests a low severity. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.10.240, < 5.10.246CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.15.189, < 5.15.196CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.1.146, < 6.1.158CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.12.39, < 6.12.56CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.15.7, < 6.16CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS data has not been published for this CVE.
No social media mentions found for this CVE.
Linux kernel (Xilinx) vulnerabilities
May 7, 2026Linux kernel (Azure) vulnerabilities
May 7, 2026Linux kernel (Azure) vulnerabilities
Apr 13, 2026Linux kernel (Azure FIPS) vulnerabilities
Apr 9, 2026Linux kernel (Azure FIPS) vulnerabilities
Apr 9, 2026Linux kernel (Raspberry Pi) vulnerabilities
Apr 1, 2026Linux kernel (Raspberry Pi) vulnerabilities
Apr 1, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (AWS) vulnerabilities
Mar 23, 2026Linux kernel (Real-time) vulnerabilities
Mar 17, 2026Linux kernel (FIPS) vulnerabilities
Mar 16, 2026Linux kernel (NVIDIA) vulnerabilities
Mar 16, 2026Linux kernel vulnerabilities
Mar 16, 2026Linux kernel (Azure) vulnerabilities
Feb 24, 2026kernel: vsock: fix lock inversion in vsock_assign_transport()
Dec 4, 2025