[ubuntu/jammy-proposed] nbd 1:3.23-3ubuntu1 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Thu Mar 10 14:55:11 UTC 2022


nbd (1:3.23-3ubuntu1) jammy; urgency=medium

  * SECURITY UPDATE: heap overflow via long name length
    - nbd-server.c: limit the size of a name length.
    - 4e5c5d2ed71cc9c34559e5fbeeb7f390661e530c
    - CVE-2022-26495
  * SECURITY UPDATE: buffer overflow in NBD_OPT_INFO/NBD_OPT_GO handling
    - nbd-server.c: use consume function instead of socket_read.
    - 3740ff7fc9c3847d309c180a1a9fc9bc895342d5
    - CVE-2022-26496

Date: Thu, 10 Mar 2022 09:08:15 -0500
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/nbd/1:3.23-3ubuntu1
-------------- next part --------------
Format: 1.8
Date: Thu, 10 Mar 2022 09:08:15 -0500
Source: nbd
Built-For-Profiles: noudeb
Architecture: source
Version: 1:3.23-3ubuntu1
Distribution: jammy
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Changes:
 nbd (1:3.23-3ubuntu1) jammy; urgency=medium
 .
   * SECURITY UPDATE: heap overflow via long name length
     - nbd-server.c: limit the size of a name length.
     - 4e5c5d2ed71cc9c34559e5fbeeb7f390661e530c
     - CVE-2022-26495
   * SECURITY UPDATE: buffer overflow in NBD_OPT_INFO/NBD_OPT_GO handling
     - nbd-server.c: use consume function instead of socket_read.
     - 3740ff7fc9c3847d309c180a1a9fc9bc895342d5
     - CVE-2022-26496
Checksums-Sha1:
 9b18a1f2c605a413ebc54ea3e48c06d9219fd157 2117 nbd_3.23-3ubuntu1.dsc
 d2ccc335c8c39ce142871863fa37f33510eadc85 92955 nbd_3.23-3ubuntu1.diff.gz
 904d3080fbcd4d3939b09d036fa8206dc37f82e7 10618 nbd_3.23-3ubuntu1_source.buildinfo
Checksums-Sha256:
 abf3d9c37cd7b63d66119f77d8e519693ab311aa080a4833807a7900fd31f4d0 2117 nbd_3.23-3ubuntu1.dsc
 f07e77688aefdad8fa51bf790c1cd5de26ee8557350186edd7e02b4d267614fe 92955 nbd_3.23-3ubuntu1.diff.gz
 dfcde7072881796122ebbcc17267d07d9cae67f00042edeaf671eecd573cf1d0 10618 nbd_3.23-3ubuntu1_source.buildinfo
Files:
 a9539d3ed78636494370057de5e3d143 2117 admin optional nbd_3.23-3ubuntu1.dsc
 db061cfe3c60fbc9231de0de0b33ca79 92955 admin optional nbd_3.23-3ubuntu1.diff.gz
 913487219480ad3a6e2a0905cf39ebb4 10618 admin optional nbd_3.23-3ubuntu1_source.buildinfo
Original-Maintainer: Wouter Verhelst <wouter at debian.org>


More information about the jammy-changes mailing list