CVE-2024-7383

Publication date 5 August 2024

Last updated 7 August 2024


Ubuntu priority

A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD server. This issue allows a man-in-the-middle attack on NBD traffic.

Status

Package Ubuntu Release Status
libnbd 24.10 oracular
Needs evaluation
24.04 LTS noble
Needs evaluation
22.04 LTS jammy
Needs evaluation
20.04 LTS focal
Needs evaluation