cbcvebase.
CVE-2025-14946
published 2025-12-19

CVE-2025-14946: A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This…

PriorityP428medium4.8CVSS 3.1
AVLACLPRLUIRSUCLILAL
EPSS
0.12%
2.0th percentile
A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrectly interpreted as arguments to the Secure Shell (SSH) process, rather than as hostnames. This could lead to arbitrary code execution with the privileges of the user running libnbd.

Affected

4 ranges
VendorProductVersion rangeFixed in
debianlibnbd< libnbd 1.22.5-1 (forky)libnbd 1.22.5-1 (forky)
red_hatlibnbd>= 1.22.0 < 1.22.51.22.5
red_hatlibnbd>= 1.23.0 < 1.23.91.23.9
redhatlibnbd>= 0 < 1.22.5-11.22.5-1

CVSS provenance

nvdv3.14.8MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
osv4.8MEDIUM
vendor_debian4.8LOW
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.