CVE-2025-47712

A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status information for a very large data range, exceeding a certain limit, it causes an internal error in the nbdkit, leading to a denial of service.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:nbdkit_project:nbdkit:-:*:*:*:*:*:*:*
OR cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_advanced_virtualization:8.0:*:*:*:*:*:*:*

History

21 Aug 2025, 01:19

Type Values Removed Values Added
First Time Redhat enterprise Linux Advanced Virtualization
Redhat
Nbdkit Project nbdkit
Nbdkit Project
Redhat enterprise Linux
References () https://access.redhat.com/security/cve/CVE-2025-47712 - () https://access.redhat.com/security/cve/CVE-2025-47712 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2365724 - () https://bugzilla.redhat.com/show_bug.cgi?id=2365724 - Issue Tracking, Third Party Advisory
References () https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/thread/67E7AASHHADIY7VAD3FFW2I67LTWVWYF/ - () https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/thread/67E7AASHHADIY7VAD3FFW2I67LTWVWYF/ - Third Party Advisory
CPE cpe:2.3:o:redhat:enterprise_linux_advanced_virtualization:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:a:nbdkit_project:nbdkit:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

29 Jul 2025, 19:15

Type Values Removed Values Added
Summary
  • (es) Existe una falla en el filtro "blocksize" de nbdkit que puede activarse con un tipo específico de solicitud de cliente. Cuando un cliente solicita información sobre el estado del bloque para un rango de datos muy grande, superando cierto límite, se produce un error interno en nbdkit, lo que provoca una denegación de servicio.
References
  • () https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/thread/67E7AASHHADIY7VAD3FFW2I67LTWVWYF/ -

09 Jun 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-09 06:15

Updated : 2025-08-21 01:19


NVD link : CVE-2025-47712

Mitre link : CVE-2025-47712

CVE.ORG link : CVE-2025-47712


JSON object : View

Products Affected

redhat

  • enterprise_linux_advanced_virtualization
  • enterprise_linux

nbdkit_project

  • nbdkit
CWE
CWE-190

Integer Overflow or Wraparound