Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-14946

Опубликовано: 19 дек. 2025
Источник: nvd
CVSS3: 4.8
EPSS Низкий

Описание

A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrectly interpreted as arguments to the Secure Shell (SSH) process, rather than as hostnames. This could lead to arbitrary code execution with the privileges of the user running libnbd.

EPSS

Процентиль: 2%
0.00123
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-88

Связанные уязвимости

CVSS3: 4.8
ubuntu
7 месяцев назад

A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrectly interpreted as arguments to the Secure Shell (SSH) process, rather than as hostnames. This could lead to arbitrary code execution with the privileges of the user running libnbd.

CVSS3: 4.8
redhat
8 месяцев назад

A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrectly interpreted as arguments to the Secure Shell (SSH) process, rather than as hostnames. This could lead to arbitrary code execution with the privileges of the user running libnbd.

CVSS3: 4.8
debian
7 месяцев назад

A flaw was found in libnbd. A malicious actor could exploit this by co ...

CVSS3: 4.8
github
7 месяцев назад

A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrectly interpreted as arguments to the Secure Shell (SSH) process, rather than as hostnames. This could lead to arbitrary code execution with the privileges of the user running libnbd.

CVSS3: 4.8
fstec
10 месяцев назад

Уязвимость набора инструментов для работы с Network Block Device Libnbd, связанная с внедрением или модификацией аргумента, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 2%
0.00123
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-88