CVE-2024-7383: Red Hat Enterprise Linux 10

High severity, CVSS 7.4. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD server. This issue allows a man-in-the-middle attack on NBD traffic.

Affected products

  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 8: before 8100020240905091210.489197e6 (fixed in 8100020240905091210.489197e6)
  • Red Hat Red Hat Enterprise Linux 8 Advanced Virtualization
  • Red Hat Red Hat Enterprise Linux 9: before 0:1.18.1-4.el9_4 (fixed in 0:1.18.1-4.el9_4)

Published 2024-08-05. Last modified 2026-06-17.