#1150366 nfs-ganesha: CVE-2026-105516 CVE-2026-105517

Package:
src:nfs-ganesha
Source:
src:nfs-ganesha
Submitter:
Salvatore Bonaccorso
Date:
2026-10-09 22:51:01 UTC
Severity:
normal
Tags:
#1150366#5
Date:
2026-10-09 05:28:52 UTC
From:
To:
Hi,

The following vulnerability was published for nfs-ganesha.

CVE-2026-105516[0]:
| 9P TWALK component count stack buffer overflow

Apparently the upstream fix planned is to remove the 9P implementation
from the next release.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-105516
https://www.cve.org/CVERecord?id=CVE-2026-105516
[1] https://bugzilla.redhat.com/show_bug.cgi?id=2545962

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1150366#10
Date:
2026-10-09 05:34:08 UTC
From:
To:
Hi,

And there is as well CVE-2026-105517, cf.
https://bugzilla.redhat.com/show_bug.cgi?id=2545966, but both covered
by removing the 9P implementation. So covering the second CVE as well
with this bugreport.

Regards,
Salvatore

#1150366#17
Date:
2026-10-09 22:49:03 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
nfs-ganesha, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1150366@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Christoph Martin <chrism@debian.org> (supplier of updated nfs-ganesha package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 09 Oct 2026 21:23:34 +0200
Source: nfs-ganesha
Architecture: source
Version: 9.14-2
Distribution: unstable
Urgency: high
Maintainer: Christoph Martin <chrism@debian.org>
Changed-By: Christoph Martin <chrism@debian.org>
Closes: 1150366
Changes:
 nfs-ganesha (9.14-2) unstable; urgency=high
 .
   * remove nfs-ganesha-mount-9p, fixes CVE-2026-105516 CVE-2026-105517
     (closes: #1150366)
Checksums-Sha1:
 6300760039c9e7bbbd7110a268f22646c7cf48a1 3572 nfs-ganesha_9.14-2.dsc
 469d2266d39ddcf1e38ec99bf8efe6567cee9f4f 21996 nfs-ganesha_9.14-2.debian.tar.xz
 854db4878c78f4cf9d7280fa67058dc863f45abc 19895 nfs-ganesha_9.14-2_amd64.buildinfo
Checksums-Sha256:
 d45b6e35ab3b7482f88566b71b5ddff365087faa5deaf87e04cd681d3074a6ab 3572 nfs-ganesha_9.14-2.dsc
 564584e7faadfefe0a0f640b6f08152d00132e435d3531990aecd346800c2ac6 21996 nfs-ganesha_9.14-2.debian.tar.xz
 cb958ec768e61a76e9487888ff7226683a2e483fdf19aad894e16f46d9de246c 19895 nfs-ganesha_9.14-2_amd64.buildinfo
Files:
 df721a8f1b50a86f0545861d5f208ff3 3572 net optional nfs-ganesha_9.14-2.dsc
 41a11da1635888392dc0e6d99e4ed333 21996 net optional nfs-ganesha_9.14-2.debian.tar.xz
 0d0540631ebb68d68a1cf75be1fb3647 19895 net optional nfs-ganesha_9.14-2_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEbdFebnsTnCYy4y02kcMUbl2GabQFAmrJbrsACgkQkcMUbl2G
abTFwQ/5ATTqYgPHCwabdZD+PpAdGLMQY81Om7cu5kR/5QMQMp0aENf+tfIp4yef
1LHGcg9pV2GEIO2Sc2sJKsUfxJNELvvkJRQqCloNxZBoU7Pm0WEU/LbaMmOCxl24
XF6smdHW+RRyKWdA4QpMtj0FtY+nPQBuYr5gb9H4M75WJYn7g0DfVLe5XJFKu25A
AHRrLqQoqiJg8atCwX/ffNkbVRxrvdryGaoopiMYsll/4H19x27HDV+h1AFybEs3
0s5rXtA4jyRQXbcr+V/2OfQjDNwlRHFgRYssvONhKBI6hCBuDXC9USgODuN4L/z0
c07fcT1xwz44kAsoQZQU4voY7Z1qhX8exmnKIW4dlCTjLNr3mMfuDwbzsR67letA
ynUnre/93huNYLQiUEj/D3fZUpr6wlW6YR4+oTQPs7EZtC+pe8GTvHvFh9BqBDtj
ECCzDjXAIM39gVIAbcRHPx34bkeddu3sSYzcDkeXWXpMUi/BhAgyLtc3G28Jp9oi
YtLFYouktU5GQAxkDjey4NKIfwBXg056ucub3lAKPc0aSE/21MPcqqhWMP0HeCcE
sGOIl8dzcTdAbxQDYgDyNf/+Bry7EkiBJD2OuxSEK7Ck4HUrMHK7mZAIOKL6ohE/
vFbwLVS0qSUblRf/EfyVPNLsw9wxB/6jfpYq+ahS7qLmOZOkqDw=
=nTOK
-----END PGP SIGNATURE-----