CVE-2019-14842

CWE-6818 documents7 sources
Severity
9.8CRITICAL
EPSS
0.2%
top 56.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 26
Latest updateMay 24

Description

Structured reply is a feature of the newstyle NBD protocol allowing the server to send a reply in chunks. A bounds check which was supposed to test for chunk offsets smaller than the beginning of the request did not work because of signed/unsigned confusion. If one of these chunks contains a negative offset then data under control of the server is written to memory before the read buffer supplied by the client. If the read buffer is located on the stack then this allows the stack return address

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

NVDredhat/libnbd< 1.0.3
Debianlibnbd< 1.0.3-1+3
CVEListV5[unknown]/libnbd1.0.3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-xv5g-h355-j9v9: Structured reply is a feature of the newstyle NBD protocol allowing the server to send a reply in chunks2022-05-24
OSV
CVE-2019-14842: Structured reply is a feature of the newstyle NBD protocol allowing the server to send a reply in chunks2019-11-26
CVEList
CVE-2019-14842: Structured reply is a feature of the newstyle NBD protocol allowing the server to send a reply in chunks2019-11-26

📋Vendor Advisories

2
Red Hat
libnbd: remote code execution vulnerability2019-10-09
Debian
CVE-2019-14842: libnbd - Structured reply is a feature of the newstyle NBD protocol allowing the server t...2019

💬Community

2
Bugzilla
CVE-2019-14842 libnbd: remote code execution vulnerability2019-11-26
Bugzilla
CVE-2019-14842 libnbd: remote code execution vulnerability [fedora-all]2019-11-26