Skip to main content

Threats Tagged 'cve-2025-40215'

View all threats tagged with 'cve-2025-40215'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2025-40215

Threats Tagged 'cve-2025-40215'

Click on any threat for detailed analysis and mitigation recommendations

Published: 2026-01-07 Updated: 2026-03-25 Reference: CVE-2025-40215 2026-03-25 Update: Added patch versions for Ubuntu nodes with GKE. GKE Updated: 2026-03-25 Description Severity The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: CVE-2025-40215 GKE Standard clusters are impacted. GKE Autopilot clusters in the default configuration are not impacted, but might be vulnerable if you explicitly set the seccomp Unconfined profile or allow CAP_NET_ADMIN . Clusters using GKE Sandbox aren't impacted. What should I do? 2026-03-25 Update : The following versions of GKE are updated with code to fix this vulnerability on Ubuntu. Upgrade your Ubuntu node pools to the following versions or later: 1.35.2-gke.1269000 1.34.4-gke.1193000 1.33.8-gke.1169000 1.32.13-gke.1059000 1.31.14-gke.1423000 1.30.14-gke.2071000 The following minor versions are affected. Upgrade your Container-Optimized OS node pools to one of the following patch versions or later: 1.32.9-gke.1632000 1.29.15-gke.2553000 1.33.5-gke.1956000 1.34.1-gke.3556000 1.31.14-gke.1081000 1.30.14-gke.1794000 1.28.15-gke.3225000 You can apply patch versions from newer release channels if your cluster runs the same minor version in its own release channel. This feature lets you secure your nodes until the patch version becomes the default in your release channel. For details, see Run patch versions from a newer channel . High GDC (VMware) Description Severity The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: CVE-2025-40215 What should I do? Note: Patch versions and a severity assessment for GDC software for VMware are in progress. We'll update this bulletin with that information when it's available. Pending GKE on AWS Description Severity The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: CVE-2025-40215 What should I do? Note: Patch versions and a severity assessment for GKE on AWS are in progress. We'll update this bulletin with that information when it's available. Pending GKE on Azure Description Severity The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: CVE-2025-40215 What should I do? Note: Patch versions and a severity assessment for GKE on Azure are in progress. We'll update this bulletin with that information when it's available. Pending GDC (bare metal) Description Severity The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: CVE-2025-40215 What should I do? There is no action required. GDC software for bare metal isn't affected as it does not bundle an operating system in its distribution. None

Join the discussion

A high-severity vulnerability (CVE-2025-40214) in the Linux kernel's Unix domain sockets subsystem was resolved by initializing scc_index in unix_add_edge(). This flaw could lead to privilege escalation on Container-Optimized OS nodes, affecting multiple Google Kubernetes Engine (GKE) cluster types except those using GKE Sandbox. Patch versions have been released for various Container-Optimized OS node pools and Ubuntu Linux kernel packages. Bare metal GDC software is not affected. Users are advised to update to the specified patched kernel versions and reboot to apply fixes.

Join the discussion

A vulnerability in the Linux kernel's xfrm subsystem involves improper deletion of ipcomp fallback tunnels, which can lead to references remaining in kernel data structures and triggering warnings. The issue arises because fallback tunnels are deleted only when the last user state is destroyed, but references may still exist, preventing timely cleanup. This can occur due to deferred freeing of socket buffers (skbs) in TCP and IP reassembly scenarios. The fix involves deleting the fallback state immediately after the last dependent user state is deleted, ensuring proper resource cleanup and avoiding kernel warnings.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: cve-2025-40215
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses