Libnbd · Libnbd · CVE-2024-7383
**Name of the Vulnerable Software and Affected Versions**
libnbd (affected versions not specified)
**Description**
The issue is related to a flaw in the libnbd library, where the client does not always correctly verify the NBD server's certificate when using TLS to connect to an NBD server. This allows a man-in-the-middle attack on NBD traffic, potentially enabling a remote attacker to disclose protected information and impact system integrity.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.