Synopsis:
libnfs security updateSummary:
An update for libnfs is now available for openEuler-24.03-LTS-SP3Description:
Package contains a library of functions for accessing NFSv2 and NFSv3 servers from user space. It provides a low-level,asynchronous RPC library for accessing NFS protocols, an asynchronous library with POSIX-like VFS functions,and a synchronous library with POSIX-like VFS functions.
Security Fix(es):
libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a connection to a crafted NFS server. This occurs in libnfs_zdr_string in lib/libnfs-zdr.c.(CVE-2026-53689)Topic:
An update for libnfs is now available for openEuler-24.03-LTS-SP3.
openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.Severity:
HighAffected Component:
libnfs
5.0.2-3.oe2403sp35.0.2-3.oe2403sp35.0.2-3.oe2403sp35.0.2-3.oe2403sp35.0.2-3.oe2403sp35.0.2-3.oe2403sp3Exploitability
AV:NAC:HPR:NUI:RScope
S:UImpact
C:HI:HA:L7.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L