The Network Block Device Project develops a Linux kernel module that enables network-accessible block device functionality, a niche but critical component for network storage and virtualization infrastructure. Vulnerabilities observed in the project center on integer overflow and out-of-bounds write conditions, reflecting the low-level memory and state-management demands of kernel-level block I/O handling. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Network Block Device Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-26496CRITICAL In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the parsing of the name field by sending a crafted NBD_OPT_INFO | Mar 6, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-26495CRITICAL In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the name length field will cause a zero-sized b | Mar 6, 2022 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Network Block Device Project.
Media articles that mention a CVE ID that affects a product developed by Network Block Device Project — matched by CVE ID, not by vendor name.