The modern style negotiation in Network Block Device (nbd-server) 2.9.22 through 3.3 allows remote attackers to cause a denial of service (root process termination) by (1) closing the connection during negotiation or (2) specifying a name for a non-existent export.
| Software | From | Fixed in |
|---|---|---|
| wouter_verhelst / nbd | 2.9.25 | 2.9.25.x |
| wouter_verhelst / nbd | 3.1 | 3.1.x |
| wouter_verhelst / nbd | 2.9.3 | 2.9.3.x |
| wouter_verhelst / nbd | 2.9.6 | 2.9.6.x |
| wouter_verhelst / nbd | 3.1.1 | 3.1.1.x |
| wouter_verhelst / nbd | 2.9.7 | 2.9.7.x |
| wouter_verhelst / nbd | 3.3 | 3.3.x |
| wouter_verhelst / nbd | 3.2 | 3.2.x |
| wouter_verhelst / nbd | 2.9.9 | 2.9.9.x |
| wouter_verhelst / nbd | 2.9.4 | 2.9.4.x |
| wouter_verhelst / nbd | 2.9.24 | 2.9.24.x |
| wouter_verhelst / nbd | 2.9.22 | 2.9.22.x |
| wouter_verhelst / nbd | 2.9.8 | 2.9.8.x |
| wouter_verhelst / nbd | 3.0 | 3.0.x |
| wouter_verhelst / nbd | 2.9.5 | 2.9.5.x |
| wouter_verhelst / nbd | 2.9.23 | 2.9.23.x |