Denial of Service Vulnerability in nbdkit Blocksize Filter by Red Hat
CVE-2025-47712

4.3MEDIUM

What is CVE-2025-47712?

A vulnerability exists in the nbdkit 'blocksize' filter that can be exploited through crafted client requests. When a client queries block status information for a substantial data range exceeding specified limits, it triggers an internal error within nbdkit, resulting in denial of service. This flaw emphasizes the importance of monitoring client requests and applying appropriate limits to prevent service interruptions.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-47712 : Denial of Service Vulnerability in nbdkit Blocksize Filter by Red Hat