Vulnerabilities (CVE)

Filtered by vendor Redhat Subscribe
Filtered by product Enterprise Linux Advanced Virtualization
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-47711 2 Nbdkit Project, Redhat 3 Nbdkit, Enterprise Linux, Enterprise Linux Advanced Virtualization 2025-08-26 N/A 4.3 MEDIUM
There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even larger single block, the nbdkit server can encounter a critical internal error, leading to a denial-of-service.
CVE-2025-47712 2 Nbdkit Project, Redhat 3 Nbdkit, Enterprise Linux, Enterprise Linux Advanced Virtualization 2025-08-21 N/A 4.3 MEDIUM
A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status information for a very large data range, exceeding a certain limit, it causes an internal error in the nbdkit, leading to a denial of service.