Unrated severityNVD Advisory· Published Jun 9, 2025· Updated Jan 8, 2026
Nbdkit: nbdkit-server: off-by-one error when processing block status may lead to a denial of service
CVE-2025-47711
Description
There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even larger single block, the nbdkit server can encounter a critical internal error, leading to a denial-of-service.
Affected products
4- osv-coords4 versionspkg:rpm/opensuse/nbdkit&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/nbdkit&distro=openSUSE%20Tumbleweedpkg:rpm/suse/nbdkit&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP6pkg:rpm/suse/nbdkit&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP7
< 1.36.5-150400.3.9.1+ 3 more
- (no CPE)range: < 1.36.5-150400.3.9.1
- (no CPE)range: < 1.42.3-1.1
- (no CPE)range: < 1.36.5-150400.3.9.1
- (no CPE)range: < 1.40.6-150700.4.3.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- access.redhat.com/security/cve/CVE-2025-47711mitrevdb-entryx_refsource_REDHAT
- bugzilla.redhat.com/show_bug.cgimitreissue-trackingx_refsource_REDHAT
News mentions
0No linked articles in our index yet.