CVE-2026-57918

Source
https://cve.org/CVERecord?id=CVE-2026-57918
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-57918.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-57918
Downstream
Related
Published
2026-06-26T10:54:58Z
Modified
2026-08-18T18:39:48Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L CVSS Calculator
Summary
[none]
Details

libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker.

Database specific
{
    "cna_assigner":  "mitre",
    "cwe_ids":  [
        "CWE-191"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57918.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "fixed":  "935b8db712b3c6649bc57ddc276526c4a31680de"
                }
            ],
            "source":  "AFFECTED_FIELD"
        },
        {
            "extracted_events":  [
                {
                    "fixed":  "935b8db"
                }
            ],
            "source":  "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/sahlberg/libnfs

Affected ranges

Type
GIT
Repo
https://github.com/sahlberg/libnfs
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "6.0.2"
        }
    ],
    "source":  [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

libnfs-1.*
libnfs-1.10.0
libnfs-1.11.0
libnfs-1.2.0
libnfs-1.3.0
libnfs-1.4.0
libnfs-1.5.0
libnfs-1.6.0
libnfs-1.7.0
libnfs-1.8.0
libnfs-1.9.0
libnfs-1.9.2
libnfs-1.9.3
libnfs-1.9.4
libnfs-1.9.5
libnfs-1.9.6
libnfs-1.9.7
libnfs-1.9.8
libnfs-2.*
libnfs-2.0.0
libnfs-3.*
libnfs-3.0.0
libnfs-4.*
libnfs-4.0.0
libnfs-5.*
libnfs-5.0.0
libnfs-5.0.1
libnfs-5.0.2
libnfs-5.0.3
libnfs-6.*
libnfs-6.0.0
libnfs-6.0.1
libnfs-6.0.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-57918.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "284570712566584330651034856806470635471",
            "length":  8798
        },
        "id":  "CVE-2026-57918-7352184d",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/sahlberg/libnfs/commit/935b8db712b3c6649bc57ddc276526c4a31680de",
        "target":  {
            "file":  "lib/socket.c",
            "function":  "rpc_read_from_socket"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "138084248709225250735979690866698271175",
                "177616468946722988440721285205244442495",
                "150491224201801048346106050604606434149",
                "165349998117722723497884037334515316160"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-57918-871c60ed",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/sahlberg/libnfs/commit/935b8db712b3c6649bc57ddc276526c4a31680de",
        "target":  {
            "file":  "lib/socket.c"
        }
    }
]
vanir_signatures_modified
"2026-08-18T18:39:48Z"