PT-2022-2044 · Nbd+6 · Nbd+6

王多

·

Published

2022-03-06

·

Updated

2024-11-15

·

CVE-2022-26496

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions nbd versions prior to 3.24
Description The issue is related to a stack-based buffer overflow in the nbd-server. An attacker can cause a buffer overflow by sending a crafted NBD OPT INFO or NBD OPT GO message with a large value as the length of the name field. This could potentially allow a remote attacker to execute arbitrary code.
Recommendations For versions prior to 3.24, update to version 3.24 or later to resolve the issue. As a temporary workaround, consider restricting access to the nbd-server to minimize the risk of exploitation. Avoid using large values for the name field in NBD OPT INFO or NBD OPT GO messages until the issue is resolved.

Exploit

Fix

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2024-15569
ALT-PU-2024-15571
ALT-PU-2024-1889
ALT-PU-2024-2449
BDU:2022-01643
CVE-2022-26496
DSA-5100-1
MGASA-2022-0403
OPENSUSE-SU-2022_1276-1
SUSE-SU-2022:1276-1
USN-5323-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Red Os
Suse
Ubuntu
Nbd