CVE-2026-53689: Sahlberg Libnfs
High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.
libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a connection to a crafted NFS server. This occurs in libnfs_zdr_string in lib/libnfs-zdr.c.
Affected products
- Sahlberg Libnfs
Published 2026-06-10. Last modified 2026-07-19.