Updated libnfs package fixes a security vulnerability
Publication date: 23 Sep 2026Modification date: 23 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-57918
Description
libnfs through 6.0.2 before 935b8db has an xid integer underflow in
READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection
to a crafted NFS server, when the expected pdu size exceeds the absolute
pdu size from the xid/record-marker. (CVE-2026-57918)
References
SRPMS
10/core
- libnfs-6.0.2-2.2.mga10