CVE-2023-5871 Details
Description
A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network. This issue may allow a malicious NBD server to cause a Denial of Service.
A denial-of-service vulnerability has been identified in libnbd, a userspace client library for the Network Block Device (NBD) protocol, which allows access to block devices over a network. This vulnerability arises when a malicious NBD server exploits the library's handling of extended responses, particularly with the 'nbd_block_status' API. Versions of libnbd through 1.17.4 are affected, as they do not properly manage 64-bit flag values from servers that have negotiated extended headers. The flaw can be triggered by an assertion failure, causing libnbd to crash instead of returning an error indicating the response was too large for the chosen API.
Users can upgrade to libnbd version 1.18.2 or later, where this vulnerability has been fixed. Red Hat Enterprise Linux 9 users can apply the update available through the Red Hat Update System.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2024:2204 | CVE | |
| https://access.redhat.com/security/cve/CVE-2023-5871 | CVE | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2247308 | CVE | Issue TrackingVendor Advisory |
| https://lists.libguestfs.org/archives/list/[email protected]/thread/PFVUCMPFQUDC23JXSCUUPXIGDZ7XCFMD/ | CVE | Mailing ListPatch |
| https://access.redhat.com/errata/RHSA-2024:2204 | [email protected] | |
| https://access.redhat.com/security/cve/CVE-2023-5871 | [email protected] | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2247308 | [email protected] | Issue TrackingVendor Advisory |
| https://lists.libguestfs.org/archives/list/[email protected]/thread/PFVUCMPFQUDC23JXSCUUPXIGDZ7XCFMD/ | [email protected] | Mailing ListPatch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-617 | Reachable Assertion | [email protected] |
| CWE-617 | Reachable Assertion | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat libnbd | >= 1.17.4, < 1.18.2 1.19.1 |
CPE
Remediation
| |
| redhat enterprise linux | 9.0 |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Apr 30, 2024 | CVE Modified | [email protected] |
| Dec 19, 2023 | CVE Modified | [email protected] |
| Dec 13, 2023 | CVE Modified | [email protected] |
| Dec 11, 2023 | Reanalysis | [email protected] |
| Dec 1, 2023 | Initial Analysis | [email protected] |
| Nov 27, 2023 | New CVE Received | [email protected] |