CVE-2019-14851
published 2021-03-18CVE-2019-14851: A denial of service vulnerability was discovered in nbdkit. A client issuing a certain sequence of commands could possibly trigger an assertion failure…
PriorityP431medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.99%
58.9th percentile
A denial of service vulnerability was discovered in nbdkit. A client issuing a certain sequence of commands could possibly trigger an assertion failure, causing nbdkit to exit. This issue only affected nbdkit versions 1.12.7, 1.14.1, and 1.15.1.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nbdkit | < nbdkit 1.14.2-1 (bookworm) | nbdkit 1.14.2-1 (bookworm) |
| nbdkit_project | nbdkit | < 1.12.7 | 1.12.7 |
| nbdkit_project | nbdkit | — | — |
| nbdkit_project | nbdkit | >= 0 < 1.14.2-1 | 1.14.2-1 |
| nbdkit_project | nbdkit | >= 0 < 1.14.2-1 | 1.14.2-1 |
| nbdkit_project | nbdkit | >= 0 < 1.14.2-1 | 1.14.2-1 |
| nbdkit_project | nbdkit | >= 0 < 1.14.2-1 | 1.14.2-1 |
| nbdkit_project | nbdkit | >= 1.14.0 < 1.14.1 | 1.14.1 |
| nbdkit_project | nbdkit | >= 1.15.0 < 1.15.1 | 1.15.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
nbdkit: assertion failure by issuing commands in the wrong order
vendor_redhat·2019-09-20·CVSS 6.5
CVE-2019-14851 [MEDIUM] CWE-617 nbdkit: assertion failure by issuing commands in the wrong order
nbdkit: assertion failure by issuing commands in the wrong order
A denial of service vulnerability was discovered in nbdkit. A client issuing a certain sequence of commands could possibly trigger an assertion failure, causing nbdkit to exit. This issue only affected nbdkit versions 1.12.7, 1.14.1, and 1.15.1.
A denial of service vulnerability was discovered in nbdkit. A client issuing a certain sequence of commands could possibly trigger an assertion failure, causing nbdkit to exit. This issue only affected nbdkit versions 1.12.7, 1.14.1, and 1.15.1.
Mitigation: If nbdkit is configured with TLS client authentication, only trusted clients can carry out this attack.
Only attackers that can connect to the nbdkit service can exploit this vulnerability. If nbdkit is not exposed over TCP (eg,
Debian
CVE-2019-14851: nbdkit - A denial of service vulnerability was discovered in nbdkit. A client issuing a c...
vendor_debian·2019·CVSS 6.5
CVE-2019-14851 [MEDIUM] CVE-2019-14851: nbdkit - A denial of service vulnerability was discovered in nbdkit. A client issuing a c...
A denial of service vulnerability was discovered in nbdkit. A client issuing a certain sequence of commands could possibly trigger an assertion failure, causing nbdkit to exit. This issue only affected nbdkit versions 1.12.7, 1.14.1, and 1.15.1.
Scope: local
bookworm: resolved (fixed in 1.14.2-1)
bullseye: resolved (fixed in 1.14.2-1)
forky: resolved (fixed in 1.14.2-1)
sid: resolved (fixed in 1.14.2-1)
trixie: resolved (fixed in 1.14.2-1)
GHSA
GHSA-hj75-x8cx-fm4w: A denial of service vulnerability was discovered in nbdkit
ghsa_unreviewed·2022-05-24
CVE-2019-14851 [MEDIUM] CWE-617 GHSA-hj75-x8cx-fm4w: A denial of service vulnerability was discovered in nbdkit
A denial of service vulnerability was discovered in nbdkit. A client issuing a certain sequence of commands could possibly trigger an assertion failure, causing nbdkit to exit. This issue only affected nbdkit versions 1.12.7, 1.14.1, and 1.15.1.
OSV
CVE-2019-14851: A denial of service vulnerability was discovered in nbdkit
osv·2021-03-18·CVSS 6.5
CVE-2019-14851 [MEDIUM] CVE-2019-14851: A denial of service vulnerability was discovered in nbdkit
A denial of service vulnerability was discovered in nbdkit. A client issuing a certain sequence of commands could possibly trigger an assertion failure, causing nbdkit to exit. This issue only affected nbdkit versions 1.12.7, 1.14.1, and 1.15.1.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-14851 nbdkit: assertion failure by issuing commands in the wrong order
bugzilla·2019-10-01·CVSS 6.5
CVE-2019-14851 [MEDIUM] CVE-2019-14851 nbdkit: assertion failure by issuing commands in the wrong order
CVE-2019-14851 nbdkit: assertion failure by issuing commands in the wrong order
The fix for the premature open flaw in nbdkit introduced a new vulnerability, in that a client issuing NBD_OPT_INFO before NBD_OPT_GO would trigger back-to-back calls to the open() callback, leading to an assertion failure because the first open() did not have a matching close(). No known nbdkit clients behaved in this way, but a crafted client could use this to cause nbdkit to exit.
Discussion:
Acknowledgments:
Name: Eric Blake (Red Hat)
---
External References:
https://www.redhat.com/archives/libguestfs/2019-September/msg00272.html
---
Mitigation:
If nbdkit is configured with TLS client authentication, only trusted clients can carry out this attack.
Only attackers that can connect to the nbdkit ser
Bugzilla
CVE-2019-14850 nbdkit: denial of service due to premature opening of back-end connection [fedora-all]
bugzilla·2019-10-01·CVSS 3.7
CVE-2019-14850 [LOW] CVE-2019-14850 nbdkit: denial of service due to premature opening of back-end connection [fedora-all]
CVE-2019-14850 nbdkit: denial of service due to premature opening of back-end connection [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
2021-03-18
Published