Upstream information

CVE-2021-20286 at MITRE

Description

A flaw was found in libnbd 1.7.3. An assertion failure in nbd_unlocked_opt_go in ilb/opt.c may lead to denial of service.

SUSE information

Overall state of this security issue: Running

This issue is currently rated as having moderate severity.

CVSS v2 Scores
CVSS detail National Vulnerability Database
Base Score 4
Vector AV:N/AC:L/Au:S/C:N/I:N/A:P
Access Vector Network
Access Complexity Low
Authentication Single
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial
CVSS v3 Scores
CVSS detail National Vulnerability Database
Base Score 2.7
Vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
Attack Vector Network
Attack Complexity Low
Privileges Required High
User Interaction None
Scope Unchanged
Confidentiality Impact None
Integrity Impact None
Availability Impact Low
CVSSv3 Version 3.1
No SUSE Bugzilla entries cross referenced.

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Enterprise Storage 7.1
SUSE Linux Enterprise High Performance Computing 15 SP3
SUSE Linux Enterprise Module for Containers 15 SP3
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server for SAP Applications 15 SP3
SUSE Manager Proxy 4.2
SUSE Manager Retail Branch Server 4.2
SUSE Manager Server 4.2
  • kubevirt-manifests >= 0.40.0-5.11.2
  • kubevirt-virtctl >= 0.40.0-5.11.2
Patchnames:
SUSE-SLE-Module-Containers-15-SP3-2021-2274
SUSE Enterprise Storage 7
SUSE Linux Enterprise High Performance Computing 15 SP2
SUSE Linux Enterprise Module for Containers 15 SP2
SUSE Linux Enterprise Server 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15 SP2
SUSE Manager Proxy 4.1
SUSE Manager Retail Branch Server 4.1
SUSE Manager Server 4.1
  • containerized-data-importer-manifests >= 1.30.0-5.3.2
  • kubevirt-manifests >= 0.40.0-5.11.2
  • kubevirt-virtctl >= 0.40.0-5.11.2
Patchnames:
SUSE-SLE-Module-Containers-15-SP2-2021-2274
SUSE Linux Enterprise High Performance Computing 15 SP7
SUSE Linux Enterprise Module for Server Applications 15 SP7
SUSE Linux Enterprise Server 15 SP7
SUSE Linux Enterprise Server for SAP Applications 15 SP7
  • libnbd >= 1.20.3-150700.1.8
  • libnbd0 >= 1.20.3-150700.1.8
  • nbdfuse >= 1.20.3-150700.1.8
Patchnames:
SUSE Linux Enterprise Module for Server Applications 15 SP7 GA libnbd-1.20.3-150700.1.8
SUSE Linux Enterprise Server 16.0
  • libnbd >= 1.22.2-160000.2.2
  • libnbd-bash-completion >= 1.22.2-160000.2.2
  • libnbd0 >= 1.22.2-160000.2.2
  • nbdfuse >= 1.22.2-160000.2.2
  • python3-libnbd >= 1.22.2-160000.2.2
Patchnames:
SUSE Linux Enterprise Server 16.0 GA libnbd-1.22.2-160000.2.2
openSUSE Leap 15.3
  • kubevirt-container-disk >= 0.40.0-5.11.2
  • kubevirt-manifests >= 0.40.0-5.11.2
  • kubevirt-tests >= 0.40.0-5.11.2
  • kubevirt-virt-api >= 0.40.0-5.11.2
  • kubevirt-virt-controller >= 0.40.0-5.11.2
  • kubevirt-virt-handler >= 0.40.0-5.11.2
  • kubevirt-virt-launcher >= 0.40.0-5.11.2
  • kubevirt-virt-operator >= 0.40.0-5.11.2
  • kubevirt-virtctl >= 0.40.0-5.11.2
Patchnames:
openSUSE-SLE-15.3-2021-2274
openSUSE Tumbleweed
  • libnbd >= 1.9.3-1.2
  • libnbd-bash-completion >= 1.9.3-1.2
  • libnbd-devel >= 1.9.3-1.2
  • libnbd0 >= 1.9.3-1.2
  • nbdfuse >= 1.9.3-1.2
Patchnames:
openSUSE-Tumbleweed-2024-10961


Status of this issue by product and package

Please note that this evaluation state might be work in progress, incomplete or outdated. Also information for service packs in the LTSS phase is only included for issues meeting the LTSS criteria. If in doubt, feel free to contact us for clarification. The updates are grouped by state of their lifecycle. SUSE product lifecycles are documented on the lifecycle page.

Product(s) Source package State
Products under Long Term Service Pack support and receiving important and critical security fixes.
SUSE Linux Enterprise High Performance Computing 15 SP3 kubevirt Released
SUSE Linux Enterprise Module for Containers 15 SP3 kubevirt Released
SUSE Linux Enterprise Server 15 SP3 kubevirt Released
Products past their end of life and not receiving proactive updates anymore.
SUSE Enterprise Storage 7 containerized-data-importer Released
SUSE Enterprise Storage 7 kubevirt Released
SUSE Enterprise Storage 7.1 kubevirt Released
SUSE Linux Enterprise High Performance Computing 15 SP2 containerized-data-importer Released
SUSE Linux Enterprise High Performance Computing 15 SP2 kubevirt Released
SUSE Linux Enterprise Module for Containers 15 SP2 containerized-data-importer Released
SUSE Linux Enterprise Module for Containers 15 SP2 kubevirt Released
SUSE Linux Enterprise Server 15 SP2 containerized-data-importer Released
SUSE Linux Enterprise Server 15 SP2 kubevirt Released
SUSE Linux Enterprise Server for SAP Applications 15 SP2 containerized-data-importer Released
SUSE Linux Enterprise Server for SAP Applications 15 SP2 kubevirt Released
SUSE Linux Enterprise Server for SAP Applications 15 SP3 kubevirt Released
SUSE Manager Proxy 4.1 containerized-data-importer Released
SUSE Manager Proxy 4.1 kubevirt Released
SUSE Manager Proxy 4.2 kubevirt Released
SUSE Manager Retail Branch Server 4.1 containerized-data-importer Released
SUSE Manager Retail Branch Server 4.1 kubevirt Released
SUSE Manager Retail Branch Server 4.2 kubevirt Released
SUSE Manager Server 4.1 containerized-data-importer Released
SUSE Manager Server 4.1 kubevirt Released
SUSE Manager Server 4.2 kubevirt Released


SUSE Timeline for this CVE

CVE page created: Thu Mar 11 19:19:07 2021
CVE page last modified: Thu Dec 11 16:51:39 2025