Libnfs · Libnfs · CVE-2026-57918
**Name of the Vulnerable Software and Affected Versions**
libnfs versions prior to 6.0.2
**Description**
An integer underflow occurs in the `READ IOVEC` section of the `rpc read from socket()` function within `lib/socket.c`. This issue is triggered during a connection to a crafted NFS server when the expected PDU (Protocol Data Unit) size exceeds the absolute PDU size derived from the xid/record-marker.
**Recommendations**
Update libnfs to a version later than 6.0.2.