๐Ÿ” CVE Alert

CVE-2025-14946

MEDIUM 4.8

Libnbd: libnbd: arbitrary code execution via ssh argument injection through a malicious uri

CVSS Score
4.8
EPSS Score
0.0%
EPSS Percentile
0th

A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrectly interpreted as arguments to the Secure Shell (SSH) process, rather than as hostnames. This could lead to arbitrary code execution with the privileges of the user running libnbd.

CWE CWE-88
Vendor red hat
Product libnbd
Published Dec 19, 2025
Last Updated Dec 22, 2025
Stay Ahead of the Next One

Get instant alerts for red hat libnbd

Be the first to know when new medium vulnerabilities affecting red hat libnbd are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low

Affected Versions

Red Hat / libnbd
1.22.0 < 1.22.5 1.23.0 < 1.23.9
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/security/cve/CVE-2025-14946 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2423789 libguestfs.org: https://libguestfs.org/libnbd-release-notes-1.24.1.html#Security