Package: release.debian.org
Severity: normal
Tags: trixie
User: [email protected]
Usertags: pu


The attached debdiff for libnfs fixes CVE-2026-53689. This CVE is marked as no-dsa by the security team. Nevertheless Mitre evaluated a score of 7.1 for this CVE, which is categorized as "high".

The same patch has been uploaded to unstable some day ago as well (same version as in Trixie) and nobody complained yet.

   Thorsten
diff -Nru libnfs-5.0.2/debian/changelog libnfs-5.0.2/debian/changelog
--- libnfs-5.0.2/debian/changelog       2023-08-23 22:46:46.000000000 +0200
+++ libnfs-5.0.2/debian/changelog       2026-07-18 12:03:02.000000000 +0200
@@ -1,3 +1,12 @@
+libnfs (5.0.2-1+deb13u1) trixie; urgency=medium
+
+  * Non-maintainer upload by the LTS Team.
+  * CVE-2026-53689 (Closes: #1139731)
+    fix validation of string size to prevent integer overflow
+  * debian/control: fix Maintainer: entry
+
+ -- Thorsten Alteholz <[email protected]>  Sat, 18 Jul 2026 12:03:02 +0200
+
 libnfs (5.0.2-1) unstable; urgency=medium
 
   * debian/rules: Don't pass --parallel and --with autoreconf to dh.
diff -Nru libnfs-5.0.2/debian/control libnfs-5.0.2/debian/control
--- libnfs-5.0.2/debian/control 2023-08-23 22:46:46.000000000 +0200
+++ libnfs-5.0.2/debian/control 2026-07-09 20:00:32.000000000 +0200
@@ -1,5 +1,5 @@
 Source: libnfs
-Maintainer: Ritesh Raj Sarraf <[email protected]>,
+Maintainer: Ritesh Raj Sarraf <[email protected]>
 Uploaders: Chrysostomos Nanakos <[email protected]>
 Section: libs
 Priority: optional
diff -Nru libnfs-5.0.2/debian/patches/CVE-2026-53689.patch 
libnfs-5.0.2/debian/patches/CVE-2026-53689.patch
--- libnfs-5.0.2/debian/patches/CVE-2026-53689.patch    1970-01-01 
01:00:00.000000000 +0100
+++ libnfs-5.0.2/debian/patches/CVE-2026-53689.patch    2026-07-09 
19:55:24.000000000 +0200
@@ -0,0 +1,28 @@
+From 55c18ea33a83d667f79f0ef209c96895795c729f Mon Sep 17 00:00:00 2001
+From: Ronnie Sahlberg <[email protected]>
+Date: Wed, 10 Jun 2026 11:43:28 +1000
+Subject: [PATCH] ZDR: check the string size for sanity
+
+It could otherwise cause an overflow in the bounds check later.
+
+Reported-by: Nick Hummel <[email protected]>
+Signed-off-by: Ronnie Sahlberg <[email protected]>
+---
+ lib/libnfs-zdr.c | 4 +++-
+ 1 file changed, 3 insertions(+), 1 deletion(-)
+
+Index: libnfs-5.0.2/lib/libnfs-zdr.c
+===================================================================
+--- libnfs-5.0.2.orig/lib/libnfs-zdr.c 2026-07-09 19:51:01.617166790 +0200
++++ libnfs-5.0.2/lib/libnfs-zdr.c      2026-07-09 19:51:01.613166752 +0200
+@@ -284,7 +284,9 @@
+       if (!libnfs_zdr_u_int(zdrs, &size)) {
+               return FALSE;
+       }
+-
++      if (size > zdrs->size) {
++              return FALSE;
++      }
+       if (zdrs->pos + (int)size > zdrs->size) {
+               return FALSE;
+       }
diff -Nru libnfs-5.0.2/debian/patches/series libnfs-5.0.2/debian/patches/series
--- libnfs-5.0.2/debian/patches/series  2023-08-23 22:46:46.000000000 +0200
+++ libnfs-5.0.2/debian/patches/series  2026-07-09 19:55:35.000000000 +0200
@@ -1,2 +1,4 @@
 0001-Skip-failing-tests.patch
 0002-Skip-failing-nfs_fstat64-test.patch
+
+CVE-2026-53689.patch

Reply via email to