Vulnerabilities > CVE-2022-0485 - Unchecked Return Value vulnerability in Redhat Enterprise Linux and Libnbd

047910
CVSS 4.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
high complexity
redhat
CWE-252

Summary

A flaw was found in the copying tool `nbdcopy` of libnbd. When performing multi-threaded copies using asynchronous nbd calls, nbdcopy was blindly treating the completion of an asynchronous command as successful, rather than checking the *error parameter. This could result in the silent creation of a corrupted destination image.

Vulnerable Configurations

Part Description Count
OS
Redhat
1
Application
Redhat
102

Common Weakness Enumeration (CWE)