CVE-2023-5871: Libnbd: malicious nbd server may crash libnbd
Published Oct 31, 2023
·Updated
A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network. This issue may allow a malicious NBD server to cause a Denial of Service.
Other sources
A malicious NBD server can easily crash libnbd
Refer: https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/thread/PFVUCMPFQUDC23JXSCUUPXIGDZ7XCFMD/
— Red Hat
Affected Software
4 affected componentsFixes available
redhat/libnbd<1.18.2
1.18.2
redhat libnbd>=1.17.4<1.18.2
redhat libnbd=1.19.1
redhat Enterprise Linux=9.0
Remediation
Event History
Oct 31, 2023
Data Sourced
via Red Hat·07:12 PM
DescriptionSeverityAffected Software
Nov 27, 2023
CVE Published
via MITRE·11:58 AM
Data Sourced
via MITRE·11:58 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this flaw?
The vulnerability ID for this flaw is CVE-2023-5871.
2
What is the severity of CVE-2023-5871?
The severity of CVE-2023-5871 is high with a CVSS score of 7.5.
3
How does this vulnerability affect libnbd?
This vulnerability affects libnbd by allowing a malicious NBD server to crash it, potentially causing a Denial of Service.
4
What is the affected version of libnbd?
The affected version of libnbd is 1.18.2.
5
How can I fix CVE-2023-5871?
To fix CVE-2023-5871, update libnbd to version 1.18.2 or higher.