PT-2025-52446 · Libnbd+1 · Libnbd+1

Osidb Bzimport

·

Published

2025-10-13

·

Updated

2025-12-23

·

CVE-2025-14946

CVSS v3.1

4.8

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions libnbd (affected versions not specified)
Description A flaw exists in libnbd where a malicious actor could potentially achieve arbitrary code execution with the privileges of the user running libnbd. This is possible by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). The issue stems from an incorrect interpretation of non-standard hostnames starting with '-o', which are treated as arguments to the Secure Shell (SSH) process instead of being recognized as hostnames. A Uniform Resource Identifier (URI) is a string of characters used to identify a name or a resource.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Argument Injection

Weakness Enumeration

Related Identifiers

BDU:2026-02751
CVE-2025-14946
OPENSUSE-SU-2025:15842-1

Affected Products

Debian
Libnbd