This is an issue and not a support question which should be asked at https://forum.greenbone.net/?
Is there an existing issue for this?
Current Behavior
gvmd version: 26.24.0 (DB revision 273)
OS: Ubuntu 24.04.4 LTS, built from source
Feed version: 202607020814
During a full NVT rebuild triggered by a feed hash mismatch, update_nvts_from_osp_vts inserts into the nvts_rebuild staging table and hits a duplicate key violation on OID 1.3.6.1.4.1.25623.1.1.1.1.2003.375:
ERROR: duplicate key value violates unique constraint "nvts_rebuild_uuid_key"
DETAIL: Key (uuid)=(1.3.6.1.4.1.25623.1.1.1.1.2003.375) already exists.
This SQL error is unhandled and causes the entire gvmd process to receive an Aborted signal and crash, which then restarts, re-attempts the same rebuild, and crashes again in an infinite loop — the feed can never finish syncing.
The duplicate OID appears to originate from the same OID existing in both a NASL plugin (/var/lib/openvas/plugins/2023/debian/deb_375.nasl) and a Notus advisory (/var/lib/notus/advisories/debian.notus) simultaneously.
Expected Behavior
Expected: gvmd should catch this constraint violation, log a warning, and skip/deduplicate the conflicting row rather than crashing the whole daemon.
md main:MESSAGE:2026-07-06 10h55.51 utc:938079: Rebuilding all NVTs because of a hash value mismatch
md manage:WARNING:2026-07-06 10h57.11 utc:938079: sql_exec_internal: constraint violation: ERROR: duplicate key value violates unique constraint "nvts_rebuild_uuid_key"
DETAIL: Key (uuid)=(1.3.6.1.4.1.25623.1.1.1.1.2003.375) already exists.
md manage:WARNING:2026-07-06 10h57.11 utc:938079: sql_exec_internal: SQL: INSERT into nvts_rebuild (oid, name, summary, insight, affected, impact, cve, tag, category, family, cvss_base, creation_time, modification_time, uuid, solution_type, solution_method, solution, detection, qod, qod_type) VALUES ('1.3.6.1.4.1.25623.1.1.1.1.2003.375', 'Debian: Security Advisory (DSA-375)', 'The remote host is missing an update for the Debian ''node'' package(s) announced via the DSA-375 advisory.', 'Morgan alias SM6TKY discovered and fixed several security related problems in LinuxNode, an Amateur Packet Radio Node program. The buffer overflow he discovered can be used to gain unauthorised root access and can be remotely triggered.
For the stable distribution (woody) this problem has been fixed in version 0.3.0a-2woody1.
For the unstable distribution (sid) this problem has been fixed in version 0.3.2-1.
We recommend that you upgrade your node packages immediately.', '''node'' package(s) on Debian 3.0.', '', 'CVE-2003-0707, CVE-2003-0708', 'cvss_base_vector=AV:N/AC:L/Au:N/C:P/I:P/A:P', 3, 'Debian Local Security Checks', 7.5, 1678280204, 1706776332, '1.3.6.1.4.1.25623.1.1.1.1.2003.375', 'VendorFix', '', 'Please install the updated package(s).', 'Checks if a vulnerable package version is present on the target host.', 97, 'package');
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: gvmd: OSP: Updatin(+0x141510) [0x5a9697abd510]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: /lib/x86_64-linux-gnu/libc.so.6(+0x45330) [0x725b5ba45330]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: /lib/x86_64-linux-gnu/libc.so.6(pthread_kill+0x11c) [0x725b5ba9eb2c]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: /lib/x86_64-linux-gnu/libc.so.6(gsignal+0x1e) [0x725b5ba4527e]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: /lib/x86_64-linux-gnu/libc.so.6(abort+0xdf) [0x725b5ba288ff]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: gvmd: OSP: Updatin(+0x5c2f9) [0x5a96979d82f9]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: gvmd: OSP: Updatin(+0x13fa65) [0x5a9697abba65]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: gvmd: OSP: Updatin(+0x13e74e) [0x5a9697aba74e]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: gvmd: OSP: Updatin(+0x13ef47) [0x5a9697abaf47]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: gvmd: OSP: Updatin(+0x142abc) [0x5a9697abeabc]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: gvmd: OSP: Updatin(+0x1060ca) [0x5a9697a820ca]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: gvmd: OSP: Updatin(+0xa865e) [0x5a9697a2465e]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: gvmd: OSP: Updatin(+0x1421f7) [0x5a9697abe1f7]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: gvmd: OSP: Updatin(+0x1450cd) [0x5a9697ac10cd]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: /lib/x86_64-linux-gnu/libc.so.6(+0x2a1ca) [0x725b5ba2a1ca]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: /lib/x86_64-linux-gnu/libc.so.6(__libc_start_main+0x8b) [0x725b5ba2a28b]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: gvmd: OSP: Updatin(+0x5c365) [0x5a96979d8365]
md manage:MESSAGE:2026-07-06 10h57.11 utc:938079: Received Aborted signal
root@IAAHMCPU298:~#
Steps To Reproduce
- Have a gvmd database where nvts_feed_version in the meta table is 0 (or otherwise behind the scanner's reported feed version) while the nvts table already contains data from a prior sync.
- Start gvmd with ospd-openvas reporting a current feed version (e.g. 202607020814).
- gvmd detects the mismatch and begins update_nvts_from_osp_vts, successfully inserting ~225,000 new VTs.
- It then performs a hash comparison, finds a mismatch, and triggers "Rebuilding all NVTs."
- During that second rebuild pass, the INSERT into nvts_rebuild fails on OID 1.3.6.1.4.1.25623.1.1.1.1.2003.375 with a duplicate key violation, because this OID exists in both a NASL plugin file and a Notus advisory JSON file simultaneously.
- gvmd aborts and restarts, repeating the same failure indefinitely.
Operating System
Ubuntu 24.04.4 LTS, built from source
Version
26.24.0 (DB revision 273)
feed version: 202607020814
Anything else?
No response
This is an issue and not a support question which should be asked at https://forum.greenbone.net/?
Is there an existing issue for this?
Current Behavior
gvmd version: 26.24.0 (DB revision 273)
OS: Ubuntu 24.04.4 LTS, built from source
Feed version: 202607020814
During a full NVT rebuild triggered by a feed hash mismatch, update_nvts_from_osp_vts inserts into the nvts_rebuild staging table and hits a duplicate key violation on OID 1.3.6.1.4.1.25623.1.1.1.1.2003.375:
ERROR: duplicate key value violates unique constraint "nvts_rebuild_uuid_key"
DETAIL: Key (uuid)=(1.3.6.1.4.1.25623.1.1.1.1.2003.375) already exists.
This SQL error is unhandled and causes the entire gvmd process to receive an Aborted signal and crash, which then restarts, re-attempts the same rebuild, and crashes again in an infinite loop — the feed can never finish syncing.
The duplicate OID appears to originate from the same OID existing in both a NASL plugin (/var/lib/openvas/plugins/2023/debian/deb_375.nasl) and a Notus advisory (/var/lib/notus/advisories/debian.notus) simultaneously.
Expected Behavior
Expected: gvmd should catch this constraint violation, log a warning, and skip/deduplicate the conflicting row rather than crashing the whole daemon.
md main:MESSAGE:2026-07-06 10h55.51 utc:938079: Rebuilding all NVTs because of a hash value mismatch
md manage:WARNING:2026-07-06 10h57.11 utc:938079: sql_exec_internal: constraint violation: ERROR: duplicate key value violates unique constraint "nvts_rebuild_uuid_key"
DETAIL: Key (uuid)=(1.3.6.1.4.1.25623.1.1.1.1.2003.375) already exists.
md manage:WARNING:2026-07-06 10h57.11 utc:938079: sql_exec_internal: SQL: INSERT into nvts_rebuild (oid, name, summary, insight, affected, impact, cve, tag, category, family, cvss_base, creation_time, modification_time, uuid, solution_type, solution_method, solution, detection, qod, qod_type) VALUES ('1.3.6.1.4.1.25623.1.1.1.1.2003.375', 'Debian: Security Advisory (DSA-375)', 'The remote host is missing an update for the Debian ''node'' package(s) announced via the DSA-375 advisory.', 'Morgan alias SM6TKY discovered and fixed several security related problems in LinuxNode, an Amateur Packet Radio Node program. The buffer overflow he discovered can be used to gain unauthorised root access and can be remotely triggered.
For the stable distribution (woody) this problem has been fixed in version 0.3.0a-2woody1.
For the unstable distribution (sid) this problem has been fixed in version 0.3.2-1.
We recommend that you upgrade your node packages immediately.', '''node'' package(s) on Debian 3.0.', '', 'CVE-2003-0707, CVE-2003-0708', 'cvss_base_vector=AV:N/AC:L/Au:N/C:P/I:P/A:P', 3, 'Debian Local Security Checks', 7.5, 1678280204, 1706776332, '1.3.6.1.4.1.25623.1.1.1.1.2003.375', 'VendorFix', '', 'Please install the updated package(s).', 'Checks if a vulnerable package version is present on the target host.', 97, 'package');
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: gvmd: OSP: Updatin(+0x141510) [0x5a9697abd510]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: /lib/x86_64-linux-gnu/libc.so.6(+0x45330) [0x725b5ba45330]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: /lib/x86_64-linux-gnu/libc.so.6(pthread_kill+0x11c) [0x725b5ba9eb2c]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: /lib/x86_64-linux-gnu/libc.so.6(gsignal+0x1e) [0x725b5ba4527e]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: /lib/x86_64-linux-gnu/libc.so.6(abort+0xdf) [0x725b5ba288ff]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: gvmd: OSP: Updatin(+0x5c2f9) [0x5a96979d82f9]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: gvmd: OSP: Updatin(+0x13fa65) [0x5a9697abba65]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: gvmd: OSP: Updatin(+0x13e74e) [0x5a9697aba74e]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: gvmd: OSP: Updatin(+0x13ef47) [0x5a9697abaf47]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: gvmd: OSP: Updatin(+0x142abc) [0x5a9697abeabc]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: gvmd: OSP: Updatin(+0x1060ca) [0x5a9697a820ca]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: gvmd: OSP: Updatin(+0xa865e) [0x5a9697a2465e]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: gvmd: OSP: Updatin(+0x1421f7) [0x5a9697abe1f7]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: gvmd: OSP: Updatin(+0x1450cd) [0x5a9697ac10cd]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: /lib/x86_64-linux-gnu/libc.so.6(+0x2a1ca) [0x725b5ba2a1ca]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: /lib/x86_64-linux-gnu/libc.so.6(__libc_start_main+0x8b) [0x725b5ba2a28b]
md main:MESSAGE:2026-07-06 10h57.11 utc:938079: BACKTRACE: gvmd: OSP: Updatin(+0x5c365) [0x5a96979d8365]
md manage:MESSAGE:2026-07-06 10h57.11 utc:938079: Received Aborted signal
root@IAAHMCPU298:~#
Steps To Reproduce
Operating System
Ubuntu 24.04.4 LTS, built from source
Version
26.24.0 (DB revision 273)
feed version: 202607020814
Anything else?
No response