|
|
Log in / Subscribe / Register

Ubuntu alert USN-8464-1 (libnfs)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8464-1] LIBNFS vulnerability
Date:  Tue, 23 Jun 2026 16:14:46 +0000
Message-ID:  <E1wc3lu-00058P-Hp@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8464-1 June 23, 2026 libnfs vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: LIBNFS could be made to crash or run programs if it connected to a specially crafted NFS server. Software Description: - libnfs: NFS client library Details: It was discovered that LIBNFS incorrectly handled certain string sizes when connecting to an NFS server. An attacker could use this issue to cause LIBNFS to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libnfs-utils 5.0.2-1ubuntu1.1 libnfs14 5.0.2-1ubuntu1.1 Ubuntu 25.10 libnfs-utils 5.0.2-1ubuntu0.25.10.1 libnfs14 5.0.2-1ubuntu0.25.10.1 Ubuntu 24.04 LTS libnfs-utils 5.0.2-1ubuntu0.24.04.1 libnfs14 5.0.2-1ubuntu0.24.04.1 Ubuntu 22.04 LTS libnfs-utils 4.0.0-1ubuntu0.1 libnfs13 4.0.0-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8464-1 CVE-2026-53689 Package Information: https://launchpad.net/ubuntu/+source/libnfs/5.0.2-1ubuntu1.1 https://launchpad.net/ubuntu/+source/libnfs/5.0.2-1ubuntu... https://launchpad.net/ubuntu/+source/libnfs/5.0.2-1ubuntu... https://launchpad.net/ubuntu/+source/libnfs/4.0.0-1ubuntu0.1


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmo6sLcACgkQcpJm3tlz hgE2vw//UD9dEj/CPo0PObv+szbpvmtPxkP7Fn99FsGcvYGWoKj9LlcBWqj/sHRq 4cBQvAYW5MSFhLwbb2h73MaV8MI9TEusRnzZJES1Rsdy3ZGIHPZaVIyp3U2960jW 611zot/sAZbWC3CuKna/TQFVHkNwb0gGbqAANG46oohQETEPWqIfJLwqarouHmVl sAo7U4O/5djPQsT+JV4qV6bHThfuEqzIHusr/D0NGZqGbEiHD353BbO6r7giVij0 dU/914xq6JAkBsft5NULqCGFUyWelXZyMsJI6SpN2rSOoIxUvb2UCB1Ixx0wSqou 5dGv2ik1hYKji7+yL4SDuS8MoKnDrgGkG3eC//tISTri7b5n3ywcxILOp6fHM73u ezWJJs5AZAgq6r6SqiwIIl/vUj2pfQmSIhFs52E7/bC59XiO0RzyyuhJG/cuj815 KmQLDD3Il7kLVpxmw8pIfWq2jlWBO3uDpRNmz13vIUaTxsW+SMy1CDESr9OnbyXJ qsqJ/GFubohrxmALETeP/BrJH5UXlxr8Jg9sERt6at/WfXY2f5Cv5w+HsRTtxV2c zqsbmc6W+RpvOVAo5yjVPuigQRGmMkFBoY1wm3LT9+fW8jHtCx9rHuEON0ydKEK0 4TcU1nAS/TuUAtYF8HVrwQ7PqZ8e9BOqdpUF0ximTxCl+zrjT7I= =KOO0 -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds