In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the name length field will cause a zero-sized buffer to be allocated for the name, resulting in a write to a dangling pointer. This issue exists for the NBD_OPT_INFO, NBD_OPT_GO, and NBD_OPT_EXPORT_NAME messages.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade nbd | Aug 22, 2024 | Mar 6, 2022 |
| Debian | — | Upgrade nbd | Mar 14, 2022 | Mar 6, 2022 |
| Gentoo Linux | — | Upgrade sys-block/nbd. | Feb 5, 2024 | Mar 6, 2022 |
| Suse | — | Upgrade nbd | Oct 26, 2022 | Mar 6, 2022 |
| Ubuntu | — | Upgrade nbd-server | Mar 15, 2022 | Mar 6, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub