CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status information for a very large data range, exceeding a certain limit, it causes...Show more |
2Nbdkit Project Redhat3Enterprise Linux Enterprise Linux Advanced VirtualizationNbdkitJan 8, 2026 Jun 9, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even large...Show more |
2Nbdkit Project Redhat2Enterprise Linux NbdkitNov 21, 2024 Mar 2, 2022 N/A· v4 3.1 LOW· v3 3.5 LOW· v2 A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everythi...Show more |
A denial of service vulnerability was discovered in nbdkit. A client issuing a certain sequence of commands could possibly trigger an assertion failure, causing nbdkit to exit. This issue only affected nbdkit versions 1....Show more |
2Nbdkit Project Redhat4Enterprise Linux Enterprise Linux ServerNbdkit+1 moreNov 21, 2024 Mar 18, 2021 N/A· v4 3.7 LOW· v3 2.6 LOW· v2 A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by sim...Show more |