CVE-2025-14946
published 2025-12-19CVE-2025-14946: A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This…
PriorityP428medium4.8CVSS 3.1
AVLACLPRLUIRSUCLILAL
EPSS
0.12%
2.0th percentile
A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrectly interpreted as arguments to the Secure Shell (SSH) process, rather than as hostnames. This could lead to arbitrary code execution with the privileges of the user running libnbd.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libnbd | < libnbd 1.22.5-1 (forky) | libnbd 1.22.5-1 (forky) |
| red_hat | libnbd | >= 1.22.0 < 1.22.5 | 1.22.5 |
| red_hat | libnbd | >= 1.23.0 < 1.23.9 | 1.23.9 |
| redhat | libnbd | >= 0 < 1.22.5-1 | 1.22.5-1 |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
osv4.8MEDIUM
vendor_debian4.8LOW
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libnbd: libnbd: Arbitrary code execution via SSH argument injection through a malicious URI
vendor_redhat·2025-12-16·CVSS 4.8
CVE-2025-14946 [MEDIUM] CWE-88 libnbd: libnbd: Arbitrary code execution via SSH argument injection through a malicious URI
libnbd: libnbd: Arbitrary code execution via SSH argument injection through a malicious URI
A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrectly interpreted as arguments to the Secure Shell (SSH) process, rather than as hostnames. This could lead to arbitrary code execution with the privileges of the user running libnbd.
A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrectly interpreted as arguments to the Secure Shell (
Debian
CVE-2025-14946: libnbd - A flaw was found in libnbd. A malicious actor could exploit this by convincing l...
vendor_debian·2025·CVSS 4.8
CVE-2025-14946 [MEDIUM] CVE-2025-14946: libnbd - A flaw was found in libnbd. A malicious actor could exploit this by convincing l...
A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrectly interpreted as arguments to the Secure Shell (SSH) process, rather than as hostnames. This could lead to arbitrary code execution with the privileges of the user running libnbd.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1.22.5-1)
sid: resolved (fixed in 1.22.5-1)
trixie: open
GHSA
GHSA-mcgc-vc2p-cf7x: A flaw was found in libnbd
ghsa_unreviewed·2025-12-19
CVE-2025-14946 [MEDIUM] CWE-88 GHSA-mcgc-vc2p-cf7x: A flaw was found in libnbd
A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrectly interpreted as arguments to the Secure Shell (SSH) process, rather than as hostnames. This could lead to arbitrary code execution with the privileges of the user running libnbd.
OSV
CVE-2025-14946: A flaw was found in libnbd
osv·2025-12-19·CVSS 4.8
CVE-2025-14946 [MEDIUM] CVE-2025-14946: A flaw was found in libnbd
A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrectly interpreted as arguments to the Secure Shell (SSH) process, rather than as hostnames. This could lead to arbitrary code execution with the privileges of the user running libnbd.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-14946 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.8
CVE-2025-14946 [MEDIUM] CVE-2025-14946 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14946 :
Linux Debian vulnerability analysis and mitigation
A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrectly interpreted as arguments to the Secure Shell (SSH) process, rather than as hostnames. This could lead to arbitrary code execution with the privileges of the user running libnbd.
Source : NVD
## 4.8
Score
Published December 19, 2025
Severity MEDIUM
CNA Score 4.8
Affected Technologies
Linux Debian
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7
Exploitation Probab
Bugzilla
CVE-2025-14946 libnbd: libnbd: Arbitrary code execution via SSH argument injection through a malicious URI
bugzilla·2025-12-19·CVSS 4.8
CVE-2025-14946 [MEDIUM] CVE-2025-14946 libnbd: libnbd: Arbitrary code execution via SSH argument injection through a malicious URI
CVE-2025-14946 libnbd: libnbd: Arbitrary code execution via SSH argument injection through a malicious URI
The recent addition of nbd+ssh:// URIs to have libnbd initiate a connection to an NBD server via an ssh process did not sanitize the hostname of the ssh server. If a malicious actor can convince libnbd to open an arbitrary URI, use of non-standard hostnames beginning with '-o' would be treated as arguments to the ssh process rather than a hostname, which in turn could trigger execution of arbitrary processes under the privilege of the user running libnbd.
2025-12-19
Published