A flaw was found in libnbd. A server can reply with a block size larger than 2^63 (the NBD spec states the size is a 64-bit unsigned value). This issue could lead to an application crash or other unintended behavior for NBD clients that doesn't treat the return value of the nbd_get_size() function correctly.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-libnbdalma-upgrade-libnbd-bash-completionalma-upgrade-libnbd-develalma-upgrade-nbdfusealma-upgrade-ocaml-libnbdalma-upgrade-ocaml-libnbd-develalma-upgrade-python3-libnbd | May 8, 2024 | Sep 28, 2023 | |
| Alpine Linux | alpine-linux-upgrade-libnbd | Aug 22, 2024 | Sep 28, 2023 | |
| Debian | no-fix-debian-deb-package | May 15, 2025 | Sep 28, 2023 | |
| Oracle_linux | — | oracle-linux-upgrade-libnbdoracle-linux-upgrade-libnbd-bash-completionoracle-linux-upgrade-libnbd-develoracle-linux-upgrade-nbdfuseoracle-linux-upgrade-ocaml-libnbdoracle-linux-upgrade-ocaml-libnbd-develoracle-linux-upgrade-python3-libnbd | May 8, 2024 | Sep 21, 2023 |
| Redhat_linux | no-fix-redhat-rpm-packageredhat-upgrade-libnbdredhat-upgrade-libnbd-bash-completionredhat-upgrade-libnbd-debuginforedhat-upgrade-libnbd-debugsourceredhat-upgrade-libnbd-develredhat-upgrade-nbdfuseredhat-upgrade-nbdfuse-debuginforedhat-upgrade-ocaml-libnbdredhat-upgrade-ocaml-libnbd-debuginforedhat-upgrade-ocaml-libnbd-develredhat-upgrade-python3-libnbdredhat-upgrade-python3-libnbd-debuginfo | May 1, 2024 | Sep 28, 2023 | |
| Suse | — | suse-upgrade-libnbdsuse-upgrade-libnbd-bash-completionsuse-upgrade-libnbd-develsuse-upgrade-libnbd0suse-upgrade-nbdfusesuse-upgrade-python3-libnbd | Oct 30, 2023 | Sep 28, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub