cbcvebase.
CVE-2023-5871
published 2023-11-27

CVE-2023-5871: A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network. This issue…

medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network. This issue may allow a malicious NBD server to cause a Denial of Service.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianlibnbd< libnbd 1.18.1-1 (forky)libnbd 1.18.1-1 (forky)
gitgit>= 0 < 1:2.17.1-1ubuntu0.171:2.17.1-1ubuntu0.17
redhatenterprise_linux
redhatlibnbd
redhatlibnbd>= 0 < 1.18.1-11.18.1-1
redhatlibnbd>= 0 < 1.18.1-11.18.1-1
redhatlibnbd>= 1.17.4 < 1.18.21.18.2

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv5.5MEDIUM