CVE-2013-7441NBD vulnerability

CWE-3998 documents6 sources
Severity
7.8HIGHNVD
OSV7.5
EPSS
3.6%
top 12.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 29
Latest updateMay 17

Description

The modern style negotiation in Network Block Device (nbd-server) 2.9.22 through 3.3 allows remote attackers to cause a denial of service (root process termination) by (1) closing the connection during negotiation or (2) specifying a name for a non-existent export.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages4 packages

debiandebian/nbd< nbd 1:3.4-1 (bookworm)
Debianwouter_verhelst/nbd< 1:3.4-1+3
Ubuntuwouter_verhelst/nbd< 1:3.7-1ubuntu0.1
NVDwouter_verhelst/nbd16 versions+15

🔴Vulnerability Details

3
GHSA
GHSA-jrr7-3c28-9wx3: The modern style negotiation in Network Block Device (nbd-server) 22022-05-17
OSV
nbd vulnerabilities2015-07-22
OSV
CVE-2013-7441: The modern style negotiation in Network Block Device (nbd-server) 22015-05-29

📋Vendor Advisories

2
Ubuntu
NBD vulnerabilities2015-07-22
Debian
CVE-2013-7441: nbd - The modern style negotiation in Network Block Device (nbd-server) 2.9.22 through...2013

💬Community

2
Bugzilla
CVE-2013-7441 nbd: NBD server terminates on SIGPIPE during negotiation [epel-6]2015-05-22
Bugzilla
CVE-2013-7441 nbd: NBD server terminates on SIGPIPE during negotiation2015-05-22