PT-2023-9291 · Libnbd+5 · Libnbd+5
Pedro Sampaio
·
Published
2023-09-28
·
Updated
2024-08-06
·
CVE-2023-5215
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
libnbd (affected versions not specified)
Description
A flaw was found in libnbd where a server can reply with a block size larger than 2^63, which is a 64-bit unsigned value according to the NBD spec. This issue could lead to an application crash or other unintended behavior for NBD clients that do not treat the return value of the
nbd get size() function correctly.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Unchecked Return Value
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Almalinux
Debian
Red Hat
Red Os
Suse
Libnbd