Описание
A flaw was found in the copying tool nbdcopy
of libnbd. When performing multi-threaded copies using asynchronous nbd calls, nbdcopy was blindly treating the completion of an asynchronous command as successful, rather than checking the *error parameter. This could result in the silent creation of a corrupted destination image.
Меры по смягчению последствий
Use of nbdcopy --synchronous
will avoid undetected data corruption, but comes at a potential performance cost by avoiding the speed benefits of asynchronous operations. See the upstream security advisory for more information.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 8 Advanced Virtualization | virt:8.2/libnbd | Not affected | ||
Red Hat Enterprise Linux 8 Advanced Virtualization | virt:av/libnbd | Affected | ||
Red Hat Enterprise Linux 9 | libnbd | Not affected | ||
Advanced Virtualization for RHEL 8.4.0.EUS | virt | Fixed | RHSA-2022:0971 | 21.03.2022 |
Advanced Virtualization for RHEL 8.4.0.EUS | virt-devel | Fixed | RHSA-2022:0971 | 21.03.2022 |
Advanced Virtualization for RHEL 8.5.0.Z | virt | Fixed | RHSA-2022:0949 | 16.03.2022 |
Advanced Virtualization for RHEL 8.5.0.Z | virt-devel | Fixed | RHSA-2022:0949 | 16.03.2022 |
Advanced Virtualization for RHEL 8.6.0 | virt | Fixed | RHSA-2022:2181 | 11.05.2022 |
Advanced Virtualization for RHEL 8.6.0 | virt-devel | Fixed | RHSA-2022:2181 | 11.05.2022 |
Red Hat Enterprise Linux 8 | virt-devel | Fixed | RHSA-2022:1759 | 10.05.2022 |
Показывать по
Дополнительная информация
Статус:
4.8 Medium
CVSS3
Связанные уязвимости
A flaw was found in the copying tool `nbdcopy` of libnbd. When performing multi-threaded copies using asynchronous nbd calls, nbdcopy was blindly treating the completion of an asynchronous command as successful, rather than checking the *error parameter. This could result in the silent creation of a corrupted destination image.
A flaw was found in the copying tool `nbdcopy` of libnbd. When performing multi-threaded copies using asynchronous nbd calls, nbdcopy was blindly treating the completion of an asynchronous command as successful, rather than checking the *error parameter. This could result in the silent creation of a corrupted destination image.
A flaw was found in the copying tool `nbdcopy` of libnbd. When perform ...
4.8 Medium
CVSS3