Your message dated Thu, 23 Jul 2026 20:47:14 +0000
with message-id <[email protected]>
and subject line Bug#1139731: fixed in libnfs 5.0.2-1+deb13u1
has caused the Debian Bug report #1139731,
regarding libnfs: CVE-2026-53689
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1139731: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139731
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libnfs
Version: 5.0.2-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for libnfs.
CVE-2026-53689[0]:
| libnfs through 6.0.2 before 55c18ea does not validate a string size,
| leading to an integer overflow during a connection to a crafted NFS
| server. This occurs in libnfs_zdr_string in lib/libnfs-zdr.c.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-53689
https://www.cve.org/CVERecord?id=CVE-2026-53689
[1]
https://github.com/sahlberg/libnfs/commit/55c18ea33a83d667f79f0ef209c96895795c729f
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: libnfs
Source-Version: 5.0.2-1+deb13u1
Done: Thorsten Alteholz <[email protected]>
We believe that the bug you reported is fixed in the latest version of
libnfs, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thorsten Alteholz <[email protected]> (supplier of updated libnfs package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sat, 18 Jul 2026 12:03:02 +0200
Source: libnfs
Architecture: source
Version: 5.0.2-1+deb13u1
Distribution: trixie
Urgency: medium
Maintainer: Ritesh Raj Sarraf <[email protected]>
Changed-By: Thorsten Alteholz <[email protected]>
Closes: 1139731
Changes:
libnfs (5.0.2-1+deb13u1) trixie; urgency=medium
.
* Non-maintainer upload by the LTS Team.
* CVE-2026-53689 (Closes: #1139731)
fix validation of string size to prevent integer overflow
* debian/control: fix Maintainer: entry
Checksums-Sha1:
19a38c02b37ed842e29cef7982f18170949d85d4 2292 libnfs_5.0.2-1+deb13u1.dsc
afa9d1a272ebb505a1e782288556d56c90b2bd91 281154 libnfs_5.0.2.orig.tar.gz
10638aac307964dc591162808c07e2507301679e 12864
libnfs_5.0.2-1+deb13u1.debian.tar.xz
9712d6db0aca31ceb5b72a3decab0b561c024e1a 7213
libnfs_5.0.2-1+deb13u1_amd64.buildinfo
Checksums-Sha256:
83aa4a4695373140340472b0fc91cabff6a038f66dba62a2dfc0f8736c97a145 2292
libnfs_5.0.2-1+deb13u1.dsc
637e56643b19da9fba98f06847788c4dad308b723156a64748041035dcdf9bd3 281154
libnfs_5.0.2.orig.tar.gz
3aafd910574181ea91c460ead6fafbcdcd47a7c4a9323a4a4634d3f66d310304 12864
libnfs_5.0.2-1+deb13u1.debian.tar.xz
9632d33a95bc27ffc93c2ba5bf4990de3abdc0e92ceafdbd5bb5ef173d18747c 7213
libnfs_5.0.2-1+deb13u1_amd64.buildinfo
Files:
0578378d5babc49bac97d7d98b2ab913 2292 libs optional libnfs_5.0.2-1+deb13u1.dsc
115034aab322d05235a9555d057f8b14 281154 libs optional libnfs_5.0.2.orig.tar.gz
dbec8ae58cf085f5367865075b1f7c9c 12864 libs optional
libnfs_5.0.2-1+deb13u1.debian.tar.xz
9afa95ce90970a3f84cf932977ceb773 7213 libs optional
libnfs_5.0.2-1+deb13u1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmpcd/pfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh
bHRlaG9sei5kZQAKCRCW/KwNOHtYR5NED/46uiRn6VqXc3GYfnrsCU5xHqVZSHR6
ldhQYBo8brbTn7R9uw9raD1k1nIMAKtYp+XDEXOsIjJAhFt2SiCpLSdrXW6NnJLZ
nc53xK072uKWIvzYKFpBmji83almLMgrgyzy1TCDO6jaxvRGVKcs0ioLqjMHuqt9
We66He6FRTIsKRNDcuCua597a7ps42wzpLac8BTFWnjlg3A9GKhC/z4iQdo/kyR+
XwcbNMu6og4cx3XT0TuFe148OUOyAWSKf4lp3MIu88wwsm9cO33wdQne85N6NOTA
mmhX1Yr19aptS7tCUTfCBbobU+bEj3frC1LRXrQwPWuED70m5OzldgYshXy/6kW/
QO7B4TqKqeUnT53QiPscaUS0q3nHlSuEcBXpCymh6rkQYDC2qPxT1d94LK4yhWbG
9BxBqRiedV7my9ryjaO2TSJVjAPP+mixHN20jBMogTPV8JjIE4M+hyXm7/bQif65
O0VIeSg5teRS3lVKXAtEqTakKxRQpvrS73hzUqhQdip9sQLYC2XVOG93YdC8Vl1E
LZRXmOgCE0mXP/Ljk5cde4Jg1UJF0PPJ/jvFK/AW2tHDwUg8HuV8xuqdhXl0BgX9
jXEy1rLwYLo9bgDojC/OG1w+EQbp2hDP90zrBjnFZSSsS9xUbrxLfWuSJwZBVYlH
cJ+YjBE28v+wmA==
=GUTV
-----END PGP SIGNATURE-----
pgpvqo6LTVqwN.pgp
Description: PGP signature
--- End Message ---