Описание
A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with rpcinfo -l, address information returned by the server is copied into a fixed-size buffer without sufficient bounds checking. A malicious or compromised rpcbind server could use this flaw to crash the rpcinfo client, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Отчет
We rate the flaw as Moderate because exploitation requires a user or administrator to actively run rpcinfo -l against a malicious or compromised rpcbind endpoint (UI:R) — it cannot be triggered without that action. The demonstrated impact is limited to a crash of the rpcinfo client process; confidentiality and integrity are not affected, and no reliable code execution has been established.
Меры по смягчению последствий
To mitigate this issue, avoid using the rpcinfo -l command against untrusted, attacker-controlled, or compromised rpcbind hosts. Restrict the use of the rpcinfo utility to trusted internal endpoints or secure test environments only.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | rpcbind | Fix deferred | ||
| Red Hat Enterprise Linux 8 | rpcbind | Fix deferred | ||
| Red Hat Enterprise Linux 9 | rpcbind | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | rpcbind | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcinfo -l`, address information returned by the server is copied into a fixed-size buffer without sufficient bounds checking. A malicious or compromised rpcbind server could use this flaw to crash the rpcinfo client, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcinfo -l`, address information returned by the server is copied into a fixed-size buffer without sufficient bounds checking. A malicious or compromised rpcbind server could use this flaw to crash the rpcinfo client, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()
A stack-based buffer overflow was found in rpcbind's rpcinfo utility. ...
A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcinfo -l`, address information returned by the server is copied into a fixed-size buffer without sufficient bounds checking. A malicious or compromised rpcbind server could use this flaw to crash the rpcinfo client, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
EPSS
6.5 Medium
CVSS3