← Back

Nbdkit Project

nbdkit_project

5 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Nbdkit
nbdkit

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nbdkit Project
1Nbdkit
Jan 8, 2026
Jun 9, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status information for a very large data range, exceeding a certain limit, it causes...Show more
A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status information for a very large data range, exceeding a certain limit, it causes an internal error in the nbdkit, leading to a denial of service.Show less
2Nbdkit Project
Redhat
3Enterprise Linux
Enterprise Linux Advanced VirtualizationNbdkit
Jan 8, 2026
Jun 9, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even large...Show more
There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even larger single block, the nbdkit server can encounter a critical internal error, leading to a denial-of-service.Show less
2Nbdkit Project
Redhat
2Enterprise Linux
Nbdkit
Nov 21, 2024
Mar 2, 2022
N/A· v4
3.1 LOW· v3
3.5 LOW· v2
A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everythi...Show more
A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everything else a client sends to the server, potentially leading the client to terminate the NBD session. The highest threat from this vulnerability is to system availability.Show less
1Nbdkit Project
1Nbdkit
Nov 21, 2024
Mar 18, 2021
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
A denial of service vulnerability was discovered in nbdkit. A client issuing a certain sequence of commands could possibly trigger an assertion failure, causing nbdkit to exit. This issue only affected nbdkit versions 1....Show more
A denial of service vulnerability was discovered in nbdkit. A client issuing a certain sequence of commands could possibly trigger an assertion failure, causing nbdkit to exit. This issue only affected nbdkit versions 1.12.7, 1.14.1, and 1.15.1.Show less
2Nbdkit Project
Redhat
4Enterprise Linux
Enterprise Linux ServerNbdkit+1 more
Nov 21, 2024
Mar 18, 2021
N/A· v4
3.7 LOW· v3
2.6 LOW· v2
A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by sim...Show more
A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by simply opening a connection to the service. This vulnerability could cause resource consumption and degradation of service in nbdkit, depending on the plugins configured on the server-side.Show less