{"id":"CVE-2026-57918","details":"libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker.","modified":"2026-08-12T16:41:33.290677Z","published":"2026-06-26T10:54:58.162Z","related":["openSUSE-SU-2026:11246-1"],"database_specific":{"unresolved_ranges":[{"extracted_events":[{"fixed":"935b8db712b3c6649bc57ddc276526c4a31680de"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"fixed":"935b8db"}],"source":"DESCRIPTION"}],"cna_assigner":"mitre","cwe_ids":["CWE-191"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57918.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57918.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57918"},{"type":"FIX","url":"https://github.com/sahlberg/libnfs/commit/935b8db712b3c6649bc57ddc276526c4a31680de"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sahlberg/libnfs","events":[{"introduced":"0"},{"fixed":"18c5c73ee88bb7dc8da0d55dc95164bb77e49dc6"},{"fixed":"935b8db712b3c6649bc57ddc276526c4a31680de"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"6.0.2"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["libnfs-6.0.2","libnfs-6.0.1","libnfs-6.0.0","libnfs-5.0.3","libnfs-5.0.0","libnfs-5.0.2","libnfs-5.0.1","libnfs-4.0.0","libnfs-3.0.0","libnfs-2.0.0","libnfs-1.11.0","libnfs-1.10.0","libnfs-1.9.8","libnfs-1.9.7","libnfs-1.9.6","libnfs-1.9.5","libnfs-1.9.4","libnfs-1.9.3","libnfs-1.9.2","libnfs-1.9.0","libnfs-1.8.0","libnfs-1.7.0","libnfs-1.6.0","libnfs-1.5.0","libnfs-1.4.0","libnfs-1.3.0","libnfs-1.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-57918.json","vanir_signatures_modified":"2026-08-12T16:41:33Z","vanir_signatures":[{"deprecated":false,"digest":{"length":8798,"function_hash":"284570712566584330651034856806470635471"},"id":"CVE-2026-57918-7352184d","signature_type":"Function","signature_version":"v1","source":"https://github.com/sahlberg/libnfs/commit/935b8db712b3c6649bc57ddc276526c4a31680de","target":{"file":"lib/socket.c","function":"rpc_read_from_socket"}},{"target":{"file":"lib/socket.c"},"deprecated":false,"digest":{"line_hashes":["138084248709225250735979690866698271175","177616468946722988440721285205244442495","150491224201801048346106050604606434149","165349998117722723497884037334515316160"],"threshold":0.9},"id":"CVE-2026-57918-871c60ed","signature_type":"Line","signature_version":"v1","source":"https://github.com/sahlberg/libnfs/commit/935b8db712b3c6649bc57ddc276526c4a31680de"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L"}]}