CVE-2022-0485
NixOS vulnerability analysis and mitigation

Overview

A flaw was found in the copying tool nbdcopy of libnbd. When performing multi-threaded copies using asynchronous nbd calls, nbdcopy was blindly treating the completion of an asynchronous command as successful, rather than checking the *error parameter. This vulnerability, identified as CVE-2022-0485, could result in the silent creation of a corrupted destination image (NVD, Red Hat Bugzilla).

Technical details

The vulnerability exists in the multi-threaded copy functionality of nbdcopy when using asynchronous NBD calls. The tool fails to properly check the error parameter during command completion, leading to potential data corruption. The issue has a CVSS v3.1 Base Score of 4.8 (MEDIUM) with vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N. The flaw affects libnbd versions up to (excluding) 1.11.8 (NVD).

Impact

The vulnerability can result in two types of data corruption: when a read fails, nbdcopy blindly writes garbage to the destination; when a write fails, the tool does not flag that the destination was not written. Additionally, nbdcopy exits with a zero exit code in these failure scenarios, preventing programs running it from detecting the operation failure (Red Hat Bugzilla).

Mitigation and workarounds

The issue has been fixed in libnbd version 1.11.8. The fix involves properly checking the error parameter during asynchronous command completion and ensuring that nbdcopy fails with a non-zero exit status when errors occur. The patch was committed upstream and backported to affected versions (GitLab Commit).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22783HIGH8.1
  • NixOSNixOS
  • iris
NoYesJan 12, 2026
CVE-2026-0821MEDIUM6.9
  • NixOSNixOS
  • quickjs
NoNoJan 10, 2026
CVE-2025-68949MEDIUM5.3
  • NixOSNixOS
  • n8n
NoYesJan 13, 2026
CVE-2026-22784LOW2.3
  • NixOSNixOS
  • lychee
NoYesJan 12, 2026
CVE-2026-23497LOW1.3
  • NixOSNixOS
  • learning
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management