Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-14946

Опубликовано: 16 дек. 2025
Источник: redhat
CVSS3: 4.8

Описание

A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrectly interpreted as arguments to the Secure Shell (SSH) process, rather than as hostnames. This could lead to arbitrary code execution with the privileges of the user running libnbd.

Отчет

This vulnerability is rated Moderate for Red Hat because it requires a malicious actor to convince libnbd to open a specially crafted URI. This leads to arbitrary code execution due to improper handling of non-standard hostnames starting with '-o' as SSH arguments, executing code with the privileges of the user running libnbd.

Меры по смягчению последствий

To mitigate this issue, ensure that applications utilizing libnbd do not process Uniform Resource Identifiers (URIs) from untrusted or unverified sources. This vulnerability requires a malicious actor to convince libnbd to open a specially crafted URI, therefore restricting the sources of URIs processed by libnbd can reduce exposure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libnbdAffected
Red Hat Enterprise Linux 8virt:rhel/libnbdNot affected
Red Hat Enterprise Linux 9libnbdNot affected
Red Hat OpenShift Virtualization 4container-native-virtualization/virt-cdi-apiserverNot affected
Red Hat OpenShift Virtualization 4container-native-virtualization/virt-cdi-apiserver-rhel9Not affected
Red Hat OpenShift Virtualization 4container-native-virtualization/virt-cdi-clonerNot affected
Red Hat OpenShift Virtualization 4container-native-virtualization/virt-cdi-cloner-rhel9Not affected
Red Hat OpenShift Virtualization 4container-native-virtualization/virt-cdi-controllerNot affected
Red Hat OpenShift Virtualization 4container-native-virtualization/virt-cdi-controller-rhel9Not affected
Red Hat OpenShift Virtualization 4container-native-virtualization/virt-cdi-importerNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=2423789libnbd: libnbd: Arbitrary code execution via SSH argument injection through a malicious URI

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
7 месяцев назад

A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrectly interpreted as arguments to the Secure Shell (SSH) process, rather than as hostnames. This could lead to arbitrary code execution with the privileges of the user running libnbd.

CVSS3: 4.8
nvd
7 месяцев назад

A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrectly interpreted as arguments to the Secure Shell (SSH) process, rather than as hostnames. This could lead to arbitrary code execution with the privileges of the user running libnbd.

CVSS3: 4.8
debian
7 месяцев назад

A flaw was found in libnbd. A malicious actor could exploit this by co ...

CVSS3: 4.8
github
7 месяцев назад

A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrectly interpreted as arguments to the Secure Shell (SSH) process, rather than as hostnames. This could lead to arbitrary code execution with the privileges of the user running libnbd.

CVSS3: 4.8
fstec
10 месяцев назад

Уязвимость набора инструментов для работы с Network Block Device Libnbd, связанная с внедрением или модификацией аргумента, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

4.8 Medium

CVSS3