Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-57918

Опубликовано: 26 июн. 2026
Источник: debian
EPSS Низкий

Описание

libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libnfsnot-affectedpackage

Примечания

  • Introduced with: https://github.com/sahlberg/libnfs/commit/5e8f7ce273308eb77f94248f4501e574a703c1a5 (libnfs-6.0.0)

  • Fixed by: https://github.com/sahlberg/libnfs/commit/935b8db712b3c6649bc57ddc276526c4a31680de

EPSS

Процентиль: 9%
0.00195
Низкий

Связанные уязвимости

CVSS3: 7.1
ubuntu
3 месяца назад

libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker.

CVSS3: 7.1
nvd
3 месяца назад

libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker.

msrc
3 месяца назад

libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker.

CVSS3: 7.1
github
3 месяца назад

libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker.

EPSS

Процентиль: 9%
0.00195
Низкий