Bug 2247308 (CVE-2023-5871)

Summary: CVE-2023-5871 libnbd: Malicious NBD server may crash libnbd
Product: [Other] Security Response Reporter: Rohit Keshri <rkeshri>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: rjones, saroy, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: libnbd 1.18.2 Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network. This issue may allow a malicious NBD server to cause a Denial of Service.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2250809    
Bug Blocks: 2247303    

Description Rohit Keshri 2023-10-31 19:12:23 UTC
A malicious NBD server can easily crash libnbd

Refer:
https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/thread/PFVUCMPFQUDC23JXSCUUPXIGDZ7XCFMD/

Comment 4 Sandipan Roy 2023-11-21 09:12:47 UTC
Created libnbd tracking bugs for this issue:

Affects: fedora-all [bug 2250809]

Comment 5 Vipul Nair 2023-12-10 11:06:28 UTC
Hey Rohit shouldn't the Availability in the CVSS be marked as high as this results in a crash? If not could you drop an email to NVD?

Comment 8 errata-xmlrpc 2024-04-30 09:47:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2024:2204 https://access.redhat.com/errata/RHSA-2024:2204