CVE-2026-53689

libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a connection to a crafted NFS server. This occurs in libnfs_zdr_string in lib/libnfs-zdr.c.
Configurations

No configuration.

History

19 Jul 2026, 09:17

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2026/07/msg00031.html -

10 Jun 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-10 15:16

Updated : 2026-07-19 09:17


NVD link : CVE-2026-53689

Mitre link : CVE-2026-53689

CVE.ORG link : CVE-2026-53689


JSON object : View

Products Affected

No product.

CWE
CWE-1284

Improper Validation of Specified Quantity in Input