https://seclists.org/oss-sec/2025/q4/298: Systemd vsock sshd
Published Dec 28, 2025
·Updated
Affected Software
2 affected components
systemd systemd>=256
openssh-server
Frequently Asked Questions
1
What is the severity of CVE-2025-XXXX?
The severity of CVE-2025-XXXX is currently rated as critical due to the potential exploitation on VMs with vsock support.
2
How do I fix CVE-2025-XXXX?
To fix CVE-2025-XXXX, update the systemd and openssh-server packages to the latest versions provided by your distribution.
3
Who is affected by CVE-2025-XXXX?
CVE-2025-XXXX affects all recent VMs running on modern hypervisors that have the openssh-server package installed with vsock support.
4
What are the potential impacts of CVE-2025-XXXX?
The potential impacts of CVE-2025-XXXX include unauthorized access, data breaches, and system compromise on affected VMs.
5
When was CVE-2025-XXXX published?
CVE-2025-XXXX was published on December 28, 2025.