https://seclists.org/oss-sec/2025/q4/324: Systemd vsock sshd
Published Dec 29, 2025
·Updated
Affected Software
2 affected components
systemd systemd
apt/openssh-server
Frequently Asked Questions
1
What is the severity of CVE-2025-xxxx?
The severity of CVE-2025-xxxx is considered high due to the potential for unauthorized access to the system.
2
How do I fix CVE-2025-xxxx?
To fix CVE-2025-xxxx, you should mitigate the listener by adjusting the kernel boot string or applying kernel patches similar to those used in chromeOS.
3
What systems are affected by CVE-2025-xxxx?
CVE-2025-xxxx affects systems using systemd with the vsock functionality enabled, particularly those utilizing apt/openssh-server.
4
Is there a workaround for CVE-2025-xxxx?
Yes, you can filter address family 40 (af_vsock) at the container runtime interface to reduce exposure to CVE-2025-xxxx.
5
When was CVE-2025-xxxx published?
CVE-2025-xxxx was published on December 29, 2025.