PT-2025-52446 · Libnbd+1 · Libnbd+1
Osidb Bzimport
·
Published
2025-10-13
·
Updated
2025-12-23
·
CVE-2025-14946
CVSS v3.1
4.8
Medium
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
libnbd (affected versions not specified)
Description
A flaw exists in libnbd where a malicious actor could potentially achieve arbitrary code execution with the privileges of the user running libnbd. This is possible by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). The issue stems from an incorrect interpretation of non-standard hostnames starting with '-o', which are treated as arguments to the Secure Shell (SSH) process instead of being recognized as hostnames. A Uniform Resource Identifier (URI) is a string of characters used to identify a name or a resource.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Libnbd