First published: Tue Oct 31 2023(Updated: )
A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network. This issue may allow a malicious NBD server to cause a Denial of Service.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Libnbd | >=1.17.4<1.18.2 | |
Redhat Libnbd | =1.19.1 | |
Redhat Enterprise Linux | =9.0 | |
redhat/libnbd | <1.18.2 | 1.18.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this flaw is CVE-2023-5871.
The severity of CVE-2023-5871 is high with a CVSS score of 7.5.
This vulnerability affects libnbd by allowing a malicious NBD server to crash it, potentially causing a Denial of Service.
The affected version of libnbd is 1.18.2.
To fix CVE-2023-5871, update libnbd to version 1.18.2 or higher.