CVE-2025-40220

Service hang via synchronous fuseblk file release

Published Dec 4, 2025 · Updated May 23, 2026

Denial of service in affected Linux kernel releases allows local users to hang a fuseblk server through concurrent asynchronous I/O. When AIO completion queues delayed file puts to fuseblk server tasks, fuse_file_put sends FUSE_RELEASE synchronously until every worker waits on the same server. A local client must issue enough simultaneous AIO writes and close the associated file descriptors before completion; the resulting worker starvation halts the fuseblk service.

CVSS severityUnavailable
Unscored
EPSS probability0.19%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Denial of service in affected Linux kernel releases allows local users to hang a fuseblk server through concurrent asynchronous I/O. When AIO completion queues delayed file puts to fuseblk server tasks, fuse_file_put sends FUSE_RELEASE synchronously until every worker waits on the same server. A local client must issue enough simultaneous AIO writes and close the associated file descriptors before completion; the resulting worker starvation halts the fuseblk service.

The record

CVE
CVE-2025-40220
Published
Dec 4, 2025
Updated
May 23, 2026
Vendor
The Linux Kernel Organization
Product
Linux
Classifications
T1489
Attack vector
local
Privileges
authenticated

Timeline

How it unfolded

  1. Dec 4, 2025CVE publishedPublication date reported by the CVE source.
  2. May 23, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=23d154c71721fd0fa6199851078f32e6bd765664
  2. Affected versionversion=2.6.32.32 <2.6.33
  3. Affected versionversion=2.6.33.8 <2.6.34
  4. Affected versionversion=2.6.34.10 <2.6.35
  5. Affected versionversion=2.6.35.12 <2.6.36
  6. Affected versionversion=2.6.37.3 <2.6.38
  7. Affected versionversion=2.6.38
  8. Affected versionversion=5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 <26e5c67deb2e1f42a951f022fdf5b9f7eb747b01
  9. Affected versionversion=5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 <548e1f2bac1d4df91a6138f26bb4ab00323fd948
  10. Affected versionversion=5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 <83b375c6efef69b1066ad2d79601221e7892745a
  11. Affected versionversion=5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 <b26923512dbe57ae4917bafd31396d22a9d1691a
  12. Affected versionversion=5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 <bfd17b6138df0122a95989457d8e18ce0b86165e
  13. Affected versionversion=5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 <cfd1aa3e2b71f3327cb373c45a897c9028c62b35
  14. Affected versionversion=5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 <f19a1390af448d9e193c08e28ea5f727bf3c3049
  15. Affected versionversion=5c46eb076e0a1b2c1769287cd6942e4594ade1b1
  16. Affected versionversion=83e6726210d6c815ce044437106c738eda5ff6f6
  17. Affected versionversion=9efe56738fecd591b5bf366a325440f9b457ebd6
  18. Affected versionversion=ca3edc920f5fd7d8ac040caaf109f925c24620a0

What conditions does exploitation require?

Attack vectorlocal
Required privilegesauthenticated

What is affected?

The Linux Kernel Organization · Linuxversion=23d154c71721fd0fa6199851078f32e6bd765664; version=2.6.32.32 <2.6.33; version=2.6.33.8 <2.6.34; version=2.6.34.10 <2.6.35; version=2.6.35.12 <2.6.36; version=2.6.37.3 <2.6.38; version=2.6.38; version=5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 <26e5c67deb2e1f42a951f022fdf5b9f7eb747b01; version=5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 <548e1f2bac1d4df91a6138f26bb4ab00323fd948; version=5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 <83b375c6efef69b1066ad2d79601221e7892745a; version=5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 <b26923512dbe57ae4917bafd31396d22a9d1691a; version=5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 <bfd17b6138df0122a95989457d8e18ce0b86165e; version=5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 <cfd1aa3e2b71f3327cb373c45a897c9028c62b35; version=5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 <f19a1390af448d9e193c08e28ea5f727bf3c3049; version=5c46eb076e0a1b2c1769287cd6942e4594ade1b1; version=83e6726210d6c815ce044437106c738eda5ff6f6; version=9efe56738fecd591b5bf366a325440f9b457ebd6; version=ca3edc920f5fd7d8ac040caaf109f925c24620a0

Published CVSS scores

No CVSS assessment is available in this record.

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectorlocal
Privilegesauthenticated
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

T1489Service Stop

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo