Back

MEDIUM

Libnbd: malicious nbd server may crash libnbd

Published Nov 27, 2023

Description

A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network. This issue may allow a malicious NBD server to cause a Denial of Service.

Affected products

Remediation

Vendor solution

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Red Hat statement

Libnbd 1.16.x and earlier are not impacted, these versions gracefully reject an extended response from a malicious server as unknown since they lack extended headers support.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Nov 27, 2023
Updated Nov 20, 2025
Reserved Oct 31, 2023

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Oct 31, 2023
Bugzilla 2247308

ENISA EUVD

Assigner redhat
Published Nov 27, 2023
Updated Nov 20, 2025

GitHub

No data