VYPR

Libnfs

by Sahlberg

Source repositories

CVEs (2)

  • CVE-2026-53689HigJun 10, 2026
    risk 0.39cvss 7.1epss 0.00

    libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a connection to a crafted NFS server. This occurs in libnfs_zdr_string in lib/libnfs-zdr.c.

  • CVE-2026-57918Jun 27, 2026
    risk 0.00cvss epss 0.00

    libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker.