rpm package
opensuse/libnfs&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/libnfs&distro=openSUSE%20Tumbleweed
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-57918 | Hig | 7.1 | < 6.0.2-1.1 | 6.0.2-1.1 | Jun 26, 2026 | libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker. | |
| CVE-2026-53689 | Hig | 7.1 | < 6.0.2-1.1 | 6.0.2-1.1 | Jun 10, 2026 | libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a connection to a crafted NFS server. This occurs in libnfs_zdr_string in lib/libnfs-zdr.c. |
- affected < 6.0.2-1.1fixed 6.0.2-1.1
libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker.
- affected < 6.0.2-1.1fixed 6.0.2-1.1
libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a connection to a crafted NFS server. This occurs in libnfs_zdr_string in lib/libnfs-zdr.c.