Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:2347-1

Опубликовано: 11 июл. 2022
Источник: suse-cvrf

Описание

Security update for libnbd

This update for libnbd fixes the following issues:

  • CVE-2022-0485: Fixed nbdcopy failure if NBD read or write fails (bsc#1195636).

Список пакетов

Container suse/sles/15.5/cdi-importer:1.55.0
libnbd0-1.9.3-150300.8.9.1
Container suse/sles/15.5/cdi-uploadserver:1.55.0
libnbd-1.9.3-150300.8.9.1
libnbd0-1.9.3-150300.8.9.1
openSUSE Leap 15.3
libnbd-1.9.3-150300.8.9.1
libnbd-bash-completion-1.9.3-150300.8.9.1
libnbd-devel-1.9.3-150300.8.9.1
libnbd0-1.9.3-150300.8.9.1
nbdfuse-1.9.3-150300.8.9.1
openSUSE Leap 15.4
libnbd-1.9.3-150300.8.9.1
libnbd-bash-completion-1.9.3-150300.8.9.1
libnbd-devel-1.9.3-150300.8.9.1
libnbd0-1.9.3-150300.8.9.1
nbdfuse-1.9.3-150300.8.9.1

Описание

A flaw was found in the copying tool `nbdcopy` of libnbd. When performing multi-threaded copies using asynchronous nbd calls, nbdcopy was blindly treating the completion of an asynchronous command as successful, rather than checking the *error parameter. This could result in the silent creation of a corrupted destination image.


Затронутые продукты
Container suse/sles/15.5/cdi-importer:1.55.0:libnbd0-1.9.3-150300.8.9.1
Container suse/sles/15.5/cdi-uploadserver:1.55.0:libnbd-1.9.3-150300.8.9.1
Container suse/sles/15.5/cdi-uploadserver:1.55.0:libnbd0-1.9.3-150300.8.9.1
openSUSE Leap 15.3:libnbd-1.9.3-150300.8.9.1

Ссылки