Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-47711

Опубликовано: 23 апр. 2025
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even larger single block, the nbdkit server can encounter a critical internal error, leading to a denial-of-service.

Отчет

This vulnerability was rated as a Moderate severity by the Red Hat Product Security team. Based on the fact that while this vulnerability can be exploited remotely (AV:N) with relative ease (AC:L), it does require the attacker to have valid credentials to the target (PR:L). The primary impact is a temporary denial-of-service (A:L), meaning the server becomes unavailable, potentially disrupting dependent services. However, this exploitation does not lead to any compromise of data confidentiality (C:N) or integrity (I:N).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10nbdkitFix deferred
Red Hat Enterprise Linux 7nbdkitOut of support scope
Red Hat Enterprise Linux 8virt:rhel/nbdkitOut of support scope
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/nbdkitOut of support scope
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/nbdkitOut of support scope
Red Hat Enterprise Linux 9nbdkitFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-193
https://bugzilla.redhat.com/show_bug.cgi?id=2365687nbdkit: nbdkit-server: off-by-one error when processing block status may lead to a Denial of Service

EPSS

Процентиль: 13%
0.00043
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
10 дней назад

There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even larger single block, the nbdkit server can encounter a critical internal error, leading to a denial-of-service.

CVSS3: 4.3
nvd
10 дней назад

There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even larger single block, the nbdkit server can encounter a critical internal error, leading to a denial-of-service.

CVSS3: 4.3
debian
10 дней назад

There's a flaw in the nbdkit server when handling responses from its p ...

CVSS3: 4.3
github
10 дней назад

There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even larger single block, the nbdkit server can encounter a critical internal error, leading to a denial-of-service.

suse-cvrf
8 дней назад

Security update for nbdkit

EPSS

Процентиль: 13%
0.00043
Низкий

4.3 Medium

CVSS3