DSA-5100-1 nbd -- security update

Related Vulnerabilities: CVE-2022-26495   CVE-2022-26496  

Two vulnerabilities were discovered in the server for the Network Block Device (NBD), which could result in the execution of arbitrary code. For the oldstable distribution (buster), these problems have been fixed in version 1:3.19-3+deb10u1. For the stable distribution (bullseye), these problems have been fixed in version 1:3.21-1+deb11u1. We recommend that you upgrade your nbd packages. For the detailed security status of nbd please refer to its security tracker page at: https://security-tracker.debian.org/tracker/nbd

Debian Security Advisory

DSA-5100-1 nbd -- security update

Date Reported:
12 Mar 2022
Affected Packages:
nbd
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 1003863, Bug 1006915.
In Mitre's CVE dictionary: CVE-2022-26495, CVE-2022-26496.
More information:

Two vulnerabilities were discovered in the server for the Network Block Device (NBD), which could result in the execution of arbitrary code.

For the oldstable distribution (buster), these problems have been fixed in version 1:3.19-3+deb10u1.

For the stable distribution (bullseye), these problems have been fixed in version 1:3.21-1+deb11u1.

We recommend that you upgrade your nbd packages.

For the detailed security status of nbd please refer to its security tracker page at: https://security-tracker.debian.org/tracker/nbd