Your message dated Sun, 12 Jul 2026 17:35:07 +0000
with message-id <[email protected]>
and subject line Bug#1139731: fixed in libnfs 5.0.2-1.1
has caused the Debian Bug report #1139731,
regarding libnfs: CVE-2026-53689
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1139731: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139731
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libnfs
Version: 5.0.2-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for libnfs.
CVE-2026-53689[0]:
| libnfs through 6.0.2 before 55c18ea does not validate a string size,
| leading to an integer overflow during a connection to a crafted NFS
| server. This occurs in libnfs_zdr_string in lib/libnfs-zdr.c.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-53689
https://www.cve.org/CVERecord?id=CVE-2026-53689
[1]
https://github.com/sahlberg/libnfs/commit/55c18ea33a83d667f79f0ef209c96895795c729f
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: libnfs
Source-Version: 5.0.2-1.1
Done: Thorsten Alteholz <[email protected]>
We believe that the bug you reported is fixed in the latest version of
libnfs, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thorsten Alteholz <[email protected]> (supplier of updated libnfs package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sun, 12 Jul 2026 09:03:02 +0200
Source: libnfs
Architecture: source
Version: 5.0.2-1.1
Distribution: unstable
Urgency: medium
Maintainer: Ritesh Raj Sarraf <[email protected]>
Changed-By: Thorsten Alteholz <[email protected]>
Closes: 1139731
Changes:
libnfs (5.0.2-1.1) unstable; urgency=medium
.
* Non-maintainer upload by the LTS Team.
* CVE-2026-53689 (Closes: #1139731)
fix validation of string size to prevent integer overflow
* debian/control: fix Maintainer: entry
Checksums-Sha1:
44f0922ccd595cf9df74ae39bafa813e9b1f229b 2268 libnfs_5.0.2-1.1.dsc
afa9d1a272ebb505a1e782288556d56c90b2bd91 281154 libnfs_5.0.2.orig.tar.gz
e17360577881381c1d503a890c069338f8a43cf0 12844 libnfs_5.0.2-1.1.debian.tar.xz
4649d5b7f01090c58bcd3eb9468b671b0d3a8b99 7154 libnfs_5.0.2-1.1_amd64.buildinfo
Checksums-Sha256:
f7a835542a9792b726c6dd82286856f91de9f2e9f240e6b154b4570dfbcc7702 2268
libnfs_5.0.2-1.1.dsc
637e56643b19da9fba98f06847788c4dad308b723156a64748041035dcdf9bd3 281154
libnfs_5.0.2.orig.tar.gz
6da2456f00943586dba5e03ebd459ea83dc886e5d9ff17565d69a7080aaabcae 12844
libnfs_5.0.2-1.1.debian.tar.xz
f9e5afdce5d2e2675af2ae8e50ab8814ebaf4590be410282aae2005242132c8a 7154
libnfs_5.0.2-1.1_amd64.buildinfo
Files:
8e15172434dabf862e74eb671373461b 2268 libs optional libnfs_5.0.2-1.1.dsc
115034aab322d05235a9555d057f8b14 281154 libs optional libnfs_5.0.2.orig.tar.gz
e8fd2b35d72759d174a5cbce6f251e58 12844 libs optional
libnfs_5.0.2-1.1.debian.tar.xz
ebaa092b9ef3a6d6d7e1c255b73d991f 7154 libs optional
libnfs_5.0.2-1.1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmpTzAdfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh
bHRlaG9sei5kZQAKCRCW/KwNOHtYR+MgEADCqbAAtBm/CMGA4F4F39lANKrV0Ust
Ey5yuxNTm8bSBp9A7qyr5kMgXshU5UcjY/UgltA4cNrbHKQWvECFwnYPRXn6dIJC
iVEFVG2oWMJfqpq1lPW7ncITMB+t40qQYsK79JQDCk1GFDtHgxm5d8gPPIv/cvYE
9A4Dz/dzYG9B6VlxKVvAJ6SdUxs1ND3Kw0qZVIwPr7WhMCv3EINFxz6KxcE0wmAC
oVdpOle1DxkyAkCb/KHd78aoaSAUpS7cMlDnAxelYmAW4TspbgBJlS7gm+js7RZ8
B5H1kmQVaYkYzaqqJNtCWQm7Dk+kCF5QP3znUBZ3kqHNY5++aOi3Zr/MPzzxWmm6
RLMeNavIGFlu2jP4vanPQbVRzUO4aFue9cb8XbMDMjxcUj93T5479FqKni3UFBCz
cBFnALrMckCcl0KQyjEz4Ti+WqgkiGV/kHhkATY//W0/8PgQ/VClzG1wv+tt97mG
1k2ZfxJNQT17iJVxcVM5P6tEt7HAMhpqjNfpeo5ULT5sK6eJhpzSxU8qfKZ4xKDI
4Aw/v59S7PGJf1FlIhKv2tbSNsl7LNELgTExTc2YKRe5iSACfKDQ+b5RJZHMeqxZ
Rv/EUOkNWgOLrx9px7tg4SxwKwYjzJU9uY9Qm5nZHMVVQsUGALdKLMm9j/eiHP7A
rnbilMW7sJiXwQ==
=Iiqn
-----END PGP SIGNATURE-----
pgptPKysgmOtS.pgp
Description: PGP signature
--- End Message ---