File: nbdkit-security.pod

package info (click to toggle)
nbdkit 1.42.6-1
  • links: PTS, VCS
  • area: main
  • in suites: forky, sid
  • size: 14,700 kB
  • sloc: ansic: 59,169; sh: 16,858; makefile: 6,452; python: 1,837; cpp: 1,116; perl: 502; ml: 498; tcl: 62
file content (62 lines) | stat: -rw-r--r-- 1,908 bytes parent folder | download
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
=head1 NAME

nbdkit-security - information about past security issues in nbdkit

=head1 DESCRIPTION

This page details past security issues found in nbdkit.

For how to report new security issues, see the C<SECURITY> file in the
top level source directory, also available online here:
L<https://gitlab.com/nbdkit/nbdkit/blob/master/SECURITY>

=head2 CVE-2019-14850
denial of service due to premature opening of back-end connection

See the full announcement and links to mitigation, tests and fixes
here:
L<https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/thread/YR77GRSM2GE5W7XDXNHOPHTGCZEZ7RMP/>

=head2 CVE-2019-14851
assertion failure by issuing commands in the wrong order

This CVE was caused by the fix to the previous issue.

See the full announcement and links to mitigation, tests and fixes
here:
L<https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/message/KZMJDBRRPPVOQSD5EK6NDTXSKK6J7AYX/>

=head2 CVE-2021-3716
structured read denial of service attack against starttls

See the full announcement and links to mitigation, tests and fixes
here:
L<https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/thread/GQ6HPFKEEDTHQLO764NLGXG7YCVIENGF/>

=head2 CVE-2025-47711
denial of service attack by client sending maximum size block status

See the full announcement and links to mitigation, tests and fixes
here:
L<https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/message/67E7AASHHADIY7VAD3FFW2I67LTWVWYF/>

=head2 CVE-2025-47712
denial of service attack by client sending large unaligned size block status

See the full announcement and links to mitigation, tests and fixes
here:
L<https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/message/67E7AASHHADIY7VAD3FFW2I67LTWVWYF/>

=head1 SEE ALSO

L<nbdkit(1)>.

=head1 AUTHORS

Eric Blake

Richard W.M. Jones

=head1 COPYRIGHT

Copyright Red Hat