CVE-2025-47712

A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status information for a very large data range, exceeding a certain limit, it causes an internal error in the nbdkit, leading to a denial of service.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:nbdkit_project:nbdkit:-:*:*:*:*:*:*:*
OR cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_advanced_virtualization:8.0:*:*:*:*:*:*:*

History

21 Aug 2025, 01:19

Type Values Removed Values Added
CPE cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:a:nbdkit_project:nbdkit:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_advanced_virtualization:8.0:*:*:*:*:*:*:*
References () https://access.redhat.com/security/cve/CVE-2025-47712 - () https://access.redhat.com/security/cve/CVE-2025-47712 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2365724 - () https://bugzilla.redhat.com/show_bug.cgi?id=2365724 - Issue Tracking, Third Party Advisory
References () https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/thread/67E7AASHHADIY7VAD3FFW2I67LTWVWYF/ - () https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/thread/67E7AASHHADIY7VAD3FFW2I67LTWVWYF/ - Third Party Advisory
First Time Redhat enterprise Linux
Redhat enterprise Linux Advanced Virtualization
Nbdkit Project nbdkit
Redhat
Nbdkit Project

29 Jul 2025, 19:15

Type Values Removed Values Added
References
  • () https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/thread/67E7AASHHADIY7VAD3FFW2I67LTWVWYF/ -
Summary
  • (es) Existe una falla en el filtro "blocksize" de nbdkit que puede activarse con un tipo específico de solicitud de cliente. Cuando un cliente solicita información sobre el estado del bloque para un rango de datos muy grande, superando cierto límite, se produce un error interno en nbdkit, lo que provoca una denegación de servicio.

09 Jun 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-09 06:15

Updated : 2025-08-21 01:19


NVD link : CVE-2025-47712

Mitre link : CVE-2025-47712

CVE.ORG link : CVE-2025-47712


JSON object : View

Products Affected

nbdkit_project

  • nbdkit

redhat

  • enterprise_linux_advanced_virtualization
  • enterprise_linux
CWE
CWE-190

Integer Overflow or Wraparound