CVE-2025-47711

NameCVE-2025-47711
DescriptionThere's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even larger single block, the nbdkit server can encounter a critical internal error, leading to a denial-of-service.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1105227

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nbdkit (PTS)bullseye1.24.1-2vulnerable
bookworm1.32.5-1vulnerable
trixie, sid1.42.3-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nbdkitsource(unstable)1.42.3-11105227

Notes

[bookworm] - nbdkit <no-dsa> (Minor issue)
[bullseye] - nbdkit <postponed> (Minor issue)
https://bugzilla.redhat.com/show_bug.cgi?id=2365687
Fixed by: https://gitlab.com/nbdkit/nbdkit/-/commit/e6f96bd1b77c0cc927ce6aeff650b52238304f39 (v1.43.7)
Fixed by: https://gitlab.com/nbdkit/nbdkit/-/commit/c3c1950867ea8d9c2108ff066ed9e78dde3cfc3f (v1.42.3)

Search for package or bug name: Reporting problems