shield Security update for nbdkit
SUSE-SLE-Module-Server-Applications-15-SP7-2025-1888


This update for nbdkit fixes the following issues: Update to version 1.40.6. Security fixes: - CVE-2025-47712: integer overflow in blocksize filter when processing client block status requests larger than 2**32 will trigger an assertion failure and cause a denial-of-service. (bsc#1243108). - CVE-2025-47711: off-by-one error when processing block status results from plugins on behalf of an NBD client may trigger an assertion failure and cause a denial of service (bsc#1243110). Other fixes and changes: - golang: Support GCC 15. - openbsd: curl: Include pthread.h. - rust: Fix "overindented" list in comment. - rust: Declare explicit extern "C" API. - plugins/rust: Use CStr literals for static strings. - vddk: do_extents: Avoid reading partial chunk beyond the end of the disk. - vddk: do_extents: Exit the function if we hit req_one condition. - vddk: do_extents: Mark some local variables const. - vddk: Cache the disk size in the handle. - vddk: Include <stdbool.h>. - python: examples: Fix comment above API_VERSION constant. - tcl: Fix for Tcl 9.0 compatibility. - plugins/ocaml/NBDKit.ml: Sort bindings into order. - ocaml: Don't call abort if caml_c_thread_unregister fails. - ocaml: Use real addresses instead of (void*)<constant>s. - evil: Link to nbdkit_parse_probability(3).


cloud_download Downloads

Server Applications Module 15.7 s390x
Server Applications Module 15.7 ppc64le
Server Applications Module 15.7 aarch64
Server Applications Module 15.7 x86_64