Junglewise Threat Intelligence

CVE-2026-53689: libnfs integer overflow in libnfs_zdr_string

CVE-2026-53689 · Severity: high · CVSS 7.1 · Published 2026-06-10

Executive brief

libnfs is a client library used by applications to communicate with Network File System (NFS) storage. A vulnerability exists where the library fails to properly validate data received from a server, which could allow a malicious or compromised NFS server to crash the application or potentially gain unauthorized access to data. This risk is highest when an application connects to untrusted or public file servers.

Technical details

An integer overflow vulnerability exists in libnfs versions up to 6.0.2 within the libnfs_zdr_string function in lib/libnfs-zdr.c. The root cause is a failure to validate the string size field provided by the server before performing bounds checking. An attacker controlling a malicious NFS server can provide a large size value that causes an integer overflow during the position calculation (zdrs->pos + size), bypassing subsequent safety checks. This can lead to out-of-bounds memory access. The attack requires a client to connect to a malicious server and involves some user interaction or specific configuration (UI:R) with high complexity (AC:H). A fix is available in commit 55c18ea.

Affected products

  • sahlberg libnfs through 6.0.2 before 55c18ea

Timeline

  • 2026-06-10: disclosed: CVE published and NVD entry created
  • 2026-06-10: patched: Fix committed to libnfs repository

References

Related threats