Advisories ยป MGASA-2026-0438

Updated libnfs package fixes a security vulnerability

Publication date: 23 Sep 2026
Modification date: 23 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-57918

Description

libnfs through 6.0.2 before 935b8db has an xid integer underflow in
READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection
to a crafted NFS server, when the expected pdu size exceeds the absolute
pdu size from the xid/record-marker. (CVE-2026-57918)
                

References

SRPMS

10/core