VDB
CVE-2026-53689
CVE-2026-53689
PUBLISHED
CVSS 7.1 HIGH
Reported by mitre · Published June 10, 2026
libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a connection to a crafted NFS server. This occurs in libnfs_zdr_string in lib/libnfs-zdr.c.
Risk Scores
CVSS 3.1
7.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| sahlberg | libnfs | 0 |
| sahlberg | libnfs | 0, 0 |
Timeline
- Jun 10, 2026 CVE Published
- Jun 11, 2026 Coalition ESS Score
- Jun 12, 2026 Security Advisory
- Jul 19, 2026 CVE Updated
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Sep 5, 2026 EPSS Score