Oval Definition:oval:org.opensuse.security:def:202226495
Revision Date:2022-06-30Version:1
Title:CVE-2022-26495
Description:

In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the name length field will cause a zero-sized buffer to be allocated for the name, resulting in a write to a dangling pointer. This issue exists for the NBD_OPT_INFO, NBD_OPT_GO, and NBD_OPT_EXPORT_NAME messages.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2022-26495
SUSE CVE-2022-26495
SUSE-SU-2022:1276-1
Platform(s):openSUSE Leap 15.3
openSUSE Tumbleweed
Product(s):
Definition Synopsis
  • openSUSE Leap 15.3 is installed
  • AND Package Information
  • nbd-3.24-150000.3.3.1 is installed
  • AND nbd is signed with openSUSE key
  • Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND nbd-3.24-1.1 is installed
  • BACK