Permalink
CVE-2025-47712
4.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): NONE
- Availability impact (A): LOW
Nbd: nbdkit: integer overflow triggers an assertion resulting in denial of service
A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status information for a very large data range, exceeding a certain limit, it causes an internal error in the nbdkit, leading to a denial of service.
References
- https://access.redhat.com/security/cve/CVE-2025-47712 x_refsource_REDHAT vdb-entry
- RHBZ#2365724 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2025-47712 x_refsource_REDHAT vdb-entry
- RHBZ#2365724 issue-tracking x_refsource_REDHAT
- https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/thread/…
- RHBZ#2365724 issue-tracking x_refsource_REDHAT
- https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/thread/…
- https://access.redhat.com/security/cve/CVE-2025-47712 x_refsource_REDHAT vdb-entry
- https://access.redhat.com/security/cve/CVE-2025-47712 x_refsource_REDHAT vdb-entry
- RHBZ#2365724 issue-tracking x_refsource_REDHAT
- https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/thread/…
- https://access.redhat.com/security/cve/CVE-2025-47712 x_refsource_REDHAT vdb-entry
- RHBZ#2365724 issue-tracking x_refsource_REDHAT
- https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/thread/…
- https://access.redhat.com/security/cve/CVE-2025-47712 x_refsource_REDHAT vdb-entry
- RHBZ#2365724 issue-tracking x_refsource_REDHAT
- https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/thread/…
- https://access.redhat.com/security/cve/CVE-2025-47712 x_refsource_REDHAT vdb-entry
- RHBZ#2365724 issue-tracking x_refsource_REDHAT
- https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/thread/…
- https://access.redhat.com/security/cve/CVE-2025-47712 x_refsource_REDHAT vdb-entry
- RHBZ#2365724 issue-tracking x_refsource_REDHAT
- https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/thread/…
Affected products
nbdkit
- <1.40.6
- <1.42.3
- <1.38.6
virt:av/nbdkit
virt:8.2/nbdkit
virt:rhel/nbdkit
Package maintainers
-
@lukts30 lukts30 <llukas21307@gmail.com>