Back to search
CVE-2022-26495
Published: Mar 6, 2022
Modified: Aug 3, 2024
PUBLISHED
Description
In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the name length field will cause a zero-sized buffer to be allocated for the name, resulting in a write to a dangling pointer. This issue exists for the NBD_OPT_INFO, NBD_OPT_GO, and NBD_OPT_EXPORT_NAME messages.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
DSA-5100
vendor-advisory
FEDORA-2022-62adf9a1e0
vendor-advisory
FEDORA-2022-807e431d5f
vendor-advisory
FEDORA-2022-263873fb70
vendor-advisory
GLSA-202402-10
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now