CVE-2023-5871
published 2023-11-27CVE-2023-5871: A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network. This issue…
PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.92%
56.3th percentile
A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network. This issue may allow a malicious NBD server to cause a Denial of Service.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libnbd | < libnbd 1.18.1-1 (forky) | libnbd 1.18.1-1 (forky) |
| git | git | >= 0 < 1:2.17.1-1ubuntu0.17 | 1:2.17.1-1ubuntu0.17 |
| redhat | enterprise_linux | — | — |
| redhat | libnbd | — | — |
| redhat | libnbd | >= 0 < 1.18.1-1 | 1.18.1-1 |
| redhat | libnbd | >= 0 < 1.18.1-1 | 1.18.1-1 |
| redhat | libnbd | >= 1.17.4 < 1.18.2 | 1.18.2 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv5.5MEDIUM
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libnbd: Malicious NBD server may crash libnbd
vendor_redhat·2023-10-31·CVSS 5.3
CVE-2023-5871 [MEDIUM] CWE-617 libnbd: Malicious NBD server may crash libnbd
libnbd: Malicious NBD server may crash libnbd
A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network. This issue may allow a malicious NBD server to cause a Denial of Service.
A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network. This issue may allow a malicious NBD server to cause a Denial of Service.
Statement: Libnbd 1.16.x and earlier are not impacted, these versions gracefully reject an extended response from a malicious server as unknown since they lack extended headers support.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red H
Debian
CVE-2023-5871: libnbd - A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a pro...
vendor_debian·2023·CVSS 5.3
CVE-2023-5871 [MEDIUM] CVE-2023-5871: libnbd - A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a pro...
A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network. This issue may allow a malicious NBD server to cause a Denial of Service.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1.18.1-1)
sid: resolved (fixed in 1.18.1-1)
trixie: resolved (fixed in 1.18.1-1)
GHSA
GHSA-m8ch-v4g3-cq3g: A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network
ghsa_unreviewed·2023-11-27
CVE-2023-5871 [MEDIUM] CWE-400 GHSA-m8ch-v4g3-cq3g: A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network
A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network. This issue may allow a malicious NBD server to cause a Denial of Service.
OSV
CVE-2023-5871: A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network
osv·2023-11-27·CVSS 5.3
CVE-2023-5871 [MEDIUM] CVE-2023-5871: A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network
A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network. This issue may allow a malicious NBD server to cause a Denial of Service.
OSV
git regression
osv·2023-03-02·CVSS 5.5
CVE-2023-22490 git regression
git regression
USN-5871-1 fixed vulnerabilities in Git. A backport fixing
part of the vulnerability in CVE-2023-22490 was required.
This update fix this for Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that Git incorrectly handled certain repositories.
An attacker could use this issue to make Git uses its local
clone optimization even when using a non-local transport.
(CVE-2023-22490)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2024:2204https://access.redhat.com/security/cve/CVE-2023-5871https://bugzilla.redhat.com/show_bug.cgi?id=2247308https://lists.libguestfs.org/archives/list/[email protected]/thread/PFVUCMPFQUDC23JXSCUUPXIGDZ7XCFMD/https://access.redhat.com/errata/RHSA-2024:2204https://access.redhat.com/security/cve/CVE-2023-5871https://bugzilla.redhat.com/show_bug.cgi?id=2247308https://lists.libguestfs.org/archives/list/[email protected]/thread/PFVUCMPFQUDC23JXSCUUPXIGDZ7XCFMD/
2023-11-27
Published