Buffer overflow in the Network Block Device (nbd) server 2.7.5 and earlier, and 2.8.0 through 2.8.2, allows remote attackers to execute arbitrary code via a large request, which is written past the end of the buffer because nbd does not account for memory taken by the reply header.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade nbd | Jul 30, 2024 | Dec 22, 2005 |
| Freebsd | — | Upgrade nbd-server | Dec 10, 2025 | Dec 22, 2005 |
| Gentoo Linux | — | Upgrade sys-block/nbd. | Oct 30, 2017 | Dec 22, 2005 |
| Suse | — | Upgrade nbd | Sep 1, 2026 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub