| Package | libnfs |
|---|---|
| Version | 1.11.0-2+deb9u1 (stretch), 3.0.0-2+deb10u1 (buster) |
| Related CVEs | CVE-2026-53689 |
An issue has been found in libnfs, am NFS client library. The issue is related to to a missing validation of a string size that might lead to an integer overflow.
For Debian 10 buster, these problems have been fixed in version 3.0.0-2+deb10u1.
For Debian 9 stretch, these problems have been fixed in version 1.11.0-2+deb9u1.
We recommend that you upgrade your libnfs packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.