CVE-2011-0530Improper Restriction of Operations within the Bounds of a Memory Buffer in NBD

Severity
7.5HIGHNVD
EPSS
10.0%
top 6.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 22
Latest updateMay 17

Description

Buffer overflow in the mainloop function in nbd-server.c in the server in Network Block Device (nbd) before 2.9.20 might allow remote attackers to execute arbitrary code via a long request. NOTE: this issue exists because of a CVE-2005-3534 regression.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

debiandebian/nbd< nbd 1:2.9.16-8 (bookworm)
Debianwouter_verhelst/nbd< 1:2.9.16-8+3
NVDwouter_verhelst/nbd2.9.19+19

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8p8p-8qmp-rfr2: Buffer overflow in the mainloop function in nbd-server2022-05-17
OSV
CVE-2011-0530: Buffer overflow in the mainloop function in nbd-server2011-02-22

📋Vendor Advisories

2
Ubuntu
NBD vulnerability2011-06-21
Debian
CVE-2011-0530: nbd - Buffer overflow in the mainloop function in nbd-server.c in the server in Networ...2011

💬Community

1
Bugzilla
CVE-2011-0530 NBD: CVE-2005-3534 reintroduced in upstream nbd-v2.9.0 version2011-01-28