Libnbd: malicious nbd server may crash libnbd
Published Nov 27, 2023
5.3
MEDIUMCVSS 3.1
EPSS 0.92%
Description
A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network. This issue may allow a malicious NBD server to cause a Denial of Service.
Affected products
No data.
No data.
Red Hat Enterprise Linux 9
libnbd-0:1.18.1-3.el9
Fixed · RHSA-2024:2204
Red Hat Enterprise Linux 6
libnbd
Not affected
Red Hat Enterprise Linux 7
libnbd
Not affected
Red Hat Enterprise Linux 8
virt:rhel/libnbd
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | libnbd-0:1.18.1-3.el9 | Fixed | RHSA-2024:2204 |
| Red Hat Enterprise Linux 6 | libnbd | Not affected | n/a |
| Red Hat Enterprise Linux 7 | libnbd | Not affected | n/a |
| Red Hat Enterprise Linux 8 | virt:rhel/libnbd | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat statement
Libnbd 1.16.x and earlier are not impacted, these versions gracefully reject an extended response from a malicious server as unknown since they lack extended headers support.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (7)
- https://access.redhat.com/errata/RHSA-2024:2204 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-5871 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2247308 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-58145 Advisory
- https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/thread/PFVUCMPFQUDC23JXSCUUPXIGDZ7XCFMD/ Mailing ListPatch
- https://nvd.nist.gov/vuln/detail/CVE-2023-5871
- https://www.cve.org/CVERecord?id=CVE-2023-5871
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2024:2204 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2023-5871 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2247308 | issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-58145 | Advisory | |
| https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/thread/PFVUCMPFQUDC23JXSCUUPXIGDZ7XCFMD/ | Mailing ListPatch | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-5871 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-5871 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data