libnbd TLS Verification Vulnerability Allows Man-in-the-Middle Attack
CVE-2024-7383

7.4HIGH

Summary

A security flaw exists in libnbd impacting the verification process of the NBD server's certificate during TLS connections. This weakness can lead to a man-in-the-middle attack, compromising the integrity and confidentiality of the NBD traffic. System administrators and users of affected Red Hat products should take immediate actions to apply the necessary updates to mitigate this vulnerability and secure their environments.

Affected Version(s)

Red Hat Enterprise Linux 8 8100020240905091210.489197e6

Red Hat Enterprise Linux 8 8100020240905091210.489197e6

Red Hat Enterprise Linux 9 0:1.18.1-4.el9_4

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Jon Szymaniak for reporting this issue.
.