In the Linux kernel, the following vulnerability has been resolved:
tty: n_gsm: Don't block input queue by waiting MSC
Currently gsmqueue() processes incoming frames and when opening a DLC channel it calls gsmdlciopen() which calls gsmmodemupdate(). If basic mode is used it calls gsmmodemupdvia_msc() and it cannot block the input queue by waiting the response to come into the same input queue.
Instead allow sending Modem Status Command without waiting for remote end to respond. Define a new function gsmmodemsendinitialmsc() for this purpose. As MSC is only valid for basic encoding, it does not do anything for advanced or when convergence layer type 2 is used.
[
{
"id": "CVE-2025-40071-2695c50f",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c36785f9de03df56ff9b8eca30fa681a12b2310d",
"signature_type": "Function",
"target": {
"file": "drivers/tty/n_gsm.c",
"function": "gsm_dlci_open"
},
"deprecated": false,
"digest": {
"length": 480.0,
"function_hash": "134043278013892832285455738732948300664"
},
"signature_version": "v1"
},
{
"id": "CVE-2025-40071-28c6c81c",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5416e89b81b00443cb03c88df8da097ae091a141",
"signature_type": "Line",
"target": {
"file": "drivers/tty/n_gsm.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"268151767306188663411617724821695007120",
"231996975624041062389596841038433174792",
"311059464593458984474057210504673440993",
"198578357697286025798197509536745278301",
"164551195607169514718213731588806012019",
"317726955384970756154680314068065416295",
"197896294725526971382265478069064998253",
"159217422683437095113444109539814976325",
"77216043435248995455162549657861471330",
"173637249007987975275172683592302734992",
"158611551900104052578486846791501384000"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"id": "CVE-2025-40071-2bf8d27a",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c36785f9de03df56ff9b8eca30fa681a12b2310d",
"signature_type": "Line",
"target": {
"file": "drivers/tty/n_gsm.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"268151767306188663411617724821695007120",
"231996975624041062389596841038433174792",
"311059464593458984474057210504673440993",
"198578357697286025798197509536745278301",
"164551195607169514718213731588806012019",
"317726955384970756154680314068065416295",
"197896294725526971382265478069064998253",
"159217422683437095113444109539814976325",
"77216043435248995455162549657861471330",
"173637249007987975275172683592302734992",
"158611551900104052578486846791501384000"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"id": "CVE-2025-40071-8239c4c7",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c5a2791a7f11939f05f95c01f0aec0c55bbf28d5",
"signature_type": "Line",
"target": {
"file": "drivers/tty/n_gsm.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"268151767306188663411617724821695007120",
"231996975624041062389596841038433174792",
"311059464593458984474057210504673440993",
"198578357697286025798197509536745278301",
"164551195607169514718213731588806012019",
"317726955384970756154680314068065416295",
"197896294725526971382265478069064998253",
"159217422683437095113444109539814976325",
"77216043435248995455162549657861471330",
"173637249007987975275172683592302734992",
"158611551900104052578486846791501384000"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"id": "CVE-2025-40071-b3e5c113",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@3cf0b3c243e56bc43be560617416c1d9f301f44c",
"signature_type": "Function",
"target": {
"file": "drivers/tty/n_gsm.c",
"function": "gsm_dlci_open"
},
"deprecated": false,
"digest": {
"length": 480.0,
"function_hash": "134043278013892832285455738732948300664"
},
"signature_version": "v1"
},
{
"id": "CVE-2025-40071-c5e9b0f5",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5416e89b81b00443cb03c88df8da097ae091a141",
"signature_type": "Function",
"target": {
"file": "drivers/tty/n_gsm.c",
"function": "gsm_dlci_open"
},
"deprecated": false,
"digest": {
"length": 480.0,
"function_hash": "134043278013892832285455738732948300664"
},
"signature_version": "v1"
},
{
"id": "CVE-2025-40071-de61443a",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@3cf0b3c243e56bc43be560617416c1d9f301f44c",
"signature_type": "Line",
"target": {
"file": "drivers/tty/n_gsm.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"268151767306188663411617724821695007120",
"231996975624041062389596841038433174792",
"311059464593458984474057210504673440993",
"198578357697286025798197509536745278301",
"164551195607169514718213731588806012019",
"317726955384970756154680314068065416295",
"197896294725526971382265478069064998253",
"159217422683437095113444109539814976325",
"77216043435248995455162549657861471330",
"173637249007987975275172683592302734992",
"158611551900104052578486846791501384000"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"id": "CVE-2025-40071-e6aa976b",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c5a2791a7f11939f05f95c01f0aec0c55bbf28d5",
"signature_type": "Function",
"target": {
"file": "drivers/tty/n_gsm.c",
"function": "gsm_dlci_open"
},
"deprecated": false,
"digest": {
"length": 480.0,
"function_hash": "134043278013892832285455738732948300664"
},
"signature_version": "v1"
}
]