CVE-2022-0485: Red Hat Enterprise Linux

Medium severity, CVSS 4.8. EPSS: 1% chance of exploitation in the next 30 days.

A flaw was found in the copying tool `nbdcopy` of libnbd. When performing multi-threaded copies using asynchronous nbd calls, nbdcopy was blindly treating the completion of an asynchronous command as successful, rather than checking the *error parameter. This could result in the silent creation of a corrupted destination image.

Affected products

  • Red Hat Enterprise Linux: version 8.0 only
  • Red Hat Libnbd: before 1.11.8 (fixed in 1.11.8)

Published 2022-08-29. Last modified 2026-06-17.