CVE-2013-6410: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 2.5% chance of exploitation in the next 30 days.

nbd-server in Network Block Device (nbd) before 3.5 does not properly check IP addresses, which might allow remote attackers to bypass intended access restrictions via an IP address that has a partial match in the authfile configuration file.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 14.10 only; version 15.04 only
  • Debian Debian Linux: version 6.0 only; version 7.0 only
  • Wouter Verhelst Nbd: up to and including 3.4; version 2.7.5 only; version 2.8.0 only; version 2.8.2 only; version 2.8.4 only; version 2.8.5 only; …

Published 2013-12-07. Last modified 2026-06-17.