Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-47712

Опубликовано: 09 июн. 2025
Источник: debian
EPSS Низкий

Описание

A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status information for a very large data range, exceeding a certain limit, it causes an internal error in the nbdkit, leading to a denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nbdkitfixed1.42.3-1package
nbdkitno-dsabookwormpackage
nbdkitpostponedbullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2365724

  • Fixed by: https://gitlab.com/nbdkit/nbdkit/-/commit/a486f88d1eea653ea88b0bf8804c4825dab25ec7 (v1.43.7)

  • Fixed by: https://gitlab.com/nbdkit/nbdkit/-/commit/c3ed72811aca5684490b198737b2f0b921741547 (v1.42.3)

EPSS

Процентиль: 13%
0.00043
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
10 дней назад

A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status information for a very large data range, exceeding a certain limit, it causes an internal error in the nbdkit, leading to a denial of service.

CVSS3: 4.3
redhat
около 2 месяцев назад

A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status information for a very large data range, exceeding a certain limit, it causes an internal error in the nbdkit, leading to a denial of service.

CVSS3: 4.3
nvd
10 дней назад

A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status information for a very large data range, exceeding a certain limit, it causes an internal error in the nbdkit, leading to a denial of service.

CVSS3: 4.3
github
10 дней назад

A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status information for a very large data range, exceeding a certain limit, it causes an internal error in the nbdkit, leading to a denial of service.

suse-cvrf
8 дней назад

Security update for nbdkit

EPSS

Процентиль: 13%
0.00043
Низкий