Vulnerability Description
A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status information for a very large data range, exceeding a certain limit, it causes an internal error in the nbdkit, leading to a denial of service.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nbdkit Project | Nbdkit | - |
| Redhat | Enterprise Linux | 7.0 |
| Redhat | Enterprise Linux Advanced Virtualization | 8.0 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2025-47712Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2365724Issue TrackingThird Party Advisory
- https://lists.libguestfs.org/archives/list/[email protected]/thread/6Third Party Advisory
FAQ
What is CVE-2025-47712?
CVE-2025-47712 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status information for a very large data range, exceeding a cert...
How severe is CVE-2025-47712?
CVE-2025-47712 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-47712?
Check the references section above for vendor advisories and patch information. Affected products include: Nbdkit Project Nbdkit, Redhat Enterprise Linux, Redhat Enterprise Linux Advanced Virtualization.