CVE-2019-14851
NixOS vulnerability analysis and mitigation

Overview

A denial of service vulnerability was discovered in nbdkit, identified as CVE-2019-14851. The vulnerability affects specific versions of nbdkit (1.12.7, 1.14.1, and 1.15.1) where a client issuing certain commands in an incorrect sequence could trigger an assertion failure, causing the service to exit (CVE Mitre, Debian Tracker).

Technical details

The vulnerability was introduced as a side effect of fixing another security issue. When a client issues an NBD_OPT_INFO command before NBD_OPT_GO, it triggers back-to-back calls to the open() callback, leading to an assertion failure because the first open() did not have a matching close() operation (Red Hat Bugzilla).

Impact

When successfully exploited, this vulnerability results in a denial of service condition by causing nbdkit to exit unexpectedly. While no known nbdkit clients exhibited this behavior by default, a specially crafted client could exploit this vulnerability to force the service termination (Red Hat Bugzilla).

Exploitability

The vulnerability can only be exploited by attackers who can connect to the nbdkit service. The attack surface is limited if nbdkit is not exposed over TCP, is bound only to a private network interface, or is protected by firewall rules. Additionally, if nbdkit is configured with TLS client authentication, only trusted clients can carry out this attack (Red Hat Bugzilla).

Mitigation and workarounds

The vulnerability has been fixed in nbdkit versions 1.12.8, 1.14.2, and 1.15.2. Patches were released for different branches: 1.15 (development branch), 1.14, and 1.12, each addressing the assertion failure issue (Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91782LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91781LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91780LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91779LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-90831LOW1.9
  • NixOS logoNixOS
  • gcc-toolset-15-binutils-devel
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management