#1139731 libnfs: CVE-2026-53689

Package:
src:libnfs
Source:
src:libnfs
Submitter:
Salvatore Bonaccorso
Date:
2026-07-23 20:49:02 UTC
Severity:
normal
Tags:
#1139731#5
Date:
2026-06-12 04:28:18 UTC
From:
To:
Hi,

The following vulnerability was published for libnfs.

CVE-2026-53689[0]:
| libnfs through 6.0.2 before 55c18ea does not validate a string size,
| leading to an integer overflow during a connection to a crafted NFS
| server. This occurs in libnfs_zdr_string in lib/libnfs-zdr.c.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-53689
https://www.cve.org/CVERecord?id=CVE-2026-53689
[1] https://github.com/sahlberg/libnfs/commit/55c18ea33a83d667f79f0ef209c96895795c729f

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1139731#10
Date:
2026-06-15 13:56:47 UTC
From:
To:
Hello Balint and Chrysostomos,

Since you have been doing all the recent uploads, and given I am not active
on this package, could you please take over it as the maintainer ?
You'll also want to attend to this CVE fix. I'm assuming you use libnfs and
thus this CVE fix is important

#1139731#15
Date:
2026-06-15 14:19:37 UTC
From:
To:
Hi Ritesh & Everyone,

Ritesh Raj Sarraf <riteshsarraf@gmail.com> (időpont: 2026. jún. 15., H,
15:57) ezt írta:

I have removed myself a few years ago from Uploaders because I couldn’t
dedicate enough time and that did not change much. :-(

Best Regards,
Balint

You'll also want to attend to this CVE fix. I'm assuming you use libnfs and

#1139731#20
Date:
2026-07-12 17:35:07 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
libnfs, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1139731@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thorsten Alteholz <debian@alteholz.de> (supplier of updated libnfs package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 12 Jul 2026 09:03:02 +0200
Source: libnfs
Architecture: source
Version: 5.0.2-1.1
Distribution: unstable
Urgency: medium
Maintainer: Ritesh Raj Sarraf <rrs@debian.org>
Changed-By: Thorsten Alteholz <debian@alteholz.de>
Closes: 1139731
Changes:
 libnfs (5.0.2-1.1) unstable; urgency=medium
 .
   * Non-maintainer upload by the LTS Team.
   * CVE-2026-53689 (Closes: #1139731)
     fix validation of string size to prevent integer overflow
   * debian/control: fix Maintainer: entry
Checksums-Sha1:
 44f0922ccd595cf9df74ae39bafa813e9b1f229b 2268 libnfs_5.0.2-1.1.dsc
 afa9d1a272ebb505a1e782288556d56c90b2bd91 281154 libnfs_5.0.2.orig.tar.gz
 e17360577881381c1d503a890c069338f8a43cf0 12844 libnfs_5.0.2-1.1.debian.tar.xz
 4649d5b7f01090c58bcd3eb9468b671b0d3a8b99 7154 libnfs_5.0.2-1.1_amd64.buildinfo
Checksums-Sha256:
 f7a835542a9792b726c6dd82286856f91de9f2e9f240e6b154b4570dfbcc7702 2268 libnfs_5.0.2-1.1.dsc
 637e56643b19da9fba98f06847788c4dad308b723156a64748041035dcdf9bd3 281154 libnfs_5.0.2.orig.tar.gz
 6da2456f00943586dba5e03ebd459ea83dc886e5d9ff17565d69a7080aaabcae 12844 libnfs_5.0.2-1.1.debian.tar.xz
 f9e5afdce5d2e2675af2ae8e50ab8814ebaf4590be410282aae2005242132c8a 7154 libnfs_5.0.2-1.1_amd64.buildinfo
Files:
 8e15172434dabf862e74eb671373461b 2268 libs optional libnfs_5.0.2-1.1.dsc
 115034aab322d05235a9555d057f8b14 281154 libs optional libnfs_5.0.2.orig.tar.gz
 e8fd2b35d72759d174a5cbce6f251e58 12844 libs optional libnfs_5.0.2-1.1.debian.tar.xz
 ebaa092b9ef3a6d6d7e1c255b73d991f 7154 libs optional libnfs_5.0.2-1.1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmpTzAdfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh
bHRlaG9sei5kZQAKCRCW/KwNOHtYR+MgEADCqbAAtBm/CMGA4F4F39lANKrV0Ust
Ey5yuxNTm8bSBp9A7qyr5kMgXshU5UcjY/UgltA4cNrbHKQWvECFwnYPRXn6dIJC
iVEFVG2oWMJfqpq1lPW7ncITMB+t40qQYsK79JQDCk1GFDtHgxm5d8gPPIv/cvYE
9A4Dz/dzYG9B6VlxKVvAJ6SdUxs1ND3Kw0qZVIwPr7WhMCv3EINFxz6KxcE0wmAC
oVdpOle1DxkyAkCb/KHd78aoaSAUpS7cMlDnAxelYmAW4TspbgBJlS7gm+js7RZ8
B5H1kmQVaYkYzaqqJNtCWQm7Dk+kCF5QP3znUBZ3kqHNY5++aOi3Zr/MPzzxWmm6
RLMeNavIGFlu2jP4vanPQbVRzUO4aFue9cb8XbMDMjxcUj93T5479FqKni3UFBCz
cBFnALrMckCcl0KQyjEz4Ti+WqgkiGV/kHhkATY//W0/8PgQ/VClzG1wv+tt97mG
1k2ZfxJNQT17iJVxcVM5P6tEt7HAMhpqjNfpeo5ULT5sK6eJhpzSxU8qfKZ4xKDI
4Aw/v59S7PGJf1FlIhKv2tbSNsl7LNELgTExTc2YKRe5iSACfKDQ+b5RJZHMeqxZ
Rv/EUOkNWgOLrx9px7tg4SxwKwYjzJU9uY9Qm5nZHMVVQsUGALdKLMm9j/eiHP7A
rnbilMW7sJiXwQ==
=Iiqn
-----END PGP SIGNATURE-----

#1139731#25
Date:
2026-07-23 20:47:14 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
libnfs, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1139731@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thorsten Alteholz <debian@alteholz.de> (supplier of updated libnfs package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 18 Jul 2026 12:03:02 +0200
Source: libnfs
Architecture: source
Version: 5.0.2-1+deb13u1
Distribution: trixie
Urgency: medium
Maintainer: Ritesh Raj Sarraf <rrs@debian.org>
Changed-By: Thorsten Alteholz <debian@alteholz.de>
Closes: 1139731
Changes:
 libnfs (5.0.2-1+deb13u1) trixie; urgency=medium
 .
   * Non-maintainer upload by the LTS Team.
   * CVE-2026-53689 (Closes: #1139731)
     fix validation of string size to prevent integer overflow
   * debian/control: fix Maintainer: entry
Checksums-Sha1:
 19a38c02b37ed842e29cef7982f18170949d85d4 2292 libnfs_5.0.2-1+deb13u1.dsc
 afa9d1a272ebb505a1e782288556d56c90b2bd91 281154 libnfs_5.0.2.orig.tar.gz
 10638aac307964dc591162808c07e2507301679e 12864 libnfs_5.0.2-1+deb13u1.debian.tar.xz
 9712d6db0aca31ceb5b72a3decab0b561c024e1a 7213 libnfs_5.0.2-1+deb13u1_amd64.buildinfo
Checksums-Sha256:
 83aa4a4695373140340472b0fc91cabff6a038f66dba62a2dfc0f8736c97a145 2292 libnfs_5.0.2-1+deb13u1.dsc
 637e56643b19da9fba98f06847788c4dad308b723156a64748041035dcdf9bd3 281154 libnfs_5.0.2.orig.tar.gz
 3aafd910574181ea91c460ead6fafbcdcd47a7c4a9323a4a4634d3f66d310304 12864 libnfs_5.0.2-1+deb13u1.debian.tar.xz
 9632d33a95bc27ffc93c2ba5bf4990de3abdc0e92ceafdbd5bb5ef173d18747c 7213 libnfs_5.0.2-1+deb13u1_amd64.buildinfo
Files:
 0578378d5babc49bac97d7d98b2ab913 2292 libs optional libnfs_5.0.2-1+deb13u1.dsc
 115034aab322d05235a9555d057f8b14 281154 libs optional libnfs_5.0.2.orig.tar.gz
 dbec8ae58cf085f5367865075b1f7c9c 12864 libs optional libnfs_5.0.2-1+deb13u1.debian.tar.xz
 9afa95ce90970a3f84cf932977ceb773 7213 libs optional libnfs_5.0.2-1+deb13u1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmpcd/pfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh
bHRlaG9sei5kZQAKCRCW/KwNOHtYR5NED/46uiRn6VqXc3GYfnrsCU5xHqVZSHR6
ldhQYBo8brbTn7R9uw9raD1k1nIMAKtYp+XDEXOsIjJAhFt2SiCpLSdrXW6NnJLZ
nc53xK072uKWIvzYKFpBmji83almLMgrgyzy1TCDO6jaxvRGVKcs0ioLqjMHuqt9
We66He6FRTIsKRNDcuCua597a7ps42wzpLac8BTFWnjlg3A9GKhC/z4iQdo/kyR+
XwcbNMu6og4cx3XT0TuFe148OUOyAWSKf4lp3MIu88wwsm9cO33wdQne85N6NOTA
mmhX1Yr19aptS7tCUTfCBbobU+bEj3frC1LRXrQwPWuED70m5OzldgYshXy/6kW/
QO7B4TqKqeUnT53QiPscaUS0q3nHlSuEcBXpCymh6rkQYDC2qPxT1d94LK4yhWbG
9BxBqRiedV7my9ryjaO2TSJVjAPP+mixHN20jBMogTPV8JjIE4M+hyXm7/bQif65
O0VIeSg5teRS3lVKXAtEqTakKxRQpvrS73hzUqhQdip9sQLYC2XVOG93YdC8Vl1E
LZRXmOgCE0mXP/Ljk5cde4Jg1UJF0PPJ/jvFK/AW2tHDwUg8HuV8xuqdhXl0BgX9
jXEy1rLwYLo9bgDojC/OG1w+EQbp2hDP90zrBjnFZSSsS9xUbrxLfWuSJwZBVYlH
cJ+YjBE28v+wmA==
=GUTV
-----END PGP SIGNATURE-----