Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-16277

Опубликовано: 20 июл. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with rpcinfo -l, address information returned by the server is copied into a fixed-size buffer without sufficient bounds checking. A malicious or compromised rpcbind server could use this flaw to crash the rpcinfo client, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

Отчет

We rate the flaw as Moderate because exploitation requires a user or administrator to actively run rpcinfo -l against a malicious or compromised rpcbind endpoint (UI:R) — it cannot be triggered without that action. The demonstrated impact is limited to a crash of the rpcinfo client process; confidentiality and integrity are not affected, and no reliable code execution has been established.

Меры по смягчению последствий

To mitigate this issue, avoid using the rpcinfo -l command against untrusted, attacker-controlled, or compromised rpcbind hosts. Restrict the use of the rpcinfo utility to trusted internal endpoints or secure test environments only.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rpcbindFix deferred
Red Hat Enterprise Linux 8rpcbindFix deferred
Red Hat Enterprise Linux 9rpcbindFix deferred
Red Hat OpenShift Container Platform 4rpcbindFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=2462085rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()

EPSS

Процентиль: 20%
0.00278
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
22 дня назад

A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcinfo -l`, address information returned by the server is copied into a fixed-size buffer without sufficient bounds checking. A malicious or compromised rpcbind server could use this flaw to crash the rpcinfo client, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

CVSS3: 6.5
nvd
22 дня назад

A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcinfo -l`, address information returned by the server is copied into a fixed-size buffer without sufficient bounds checking. A malicious or compromised rpcbind server could use this flaw to crash the rpcinfo client, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

CVSS3: 6.5
msrc
19 дней назад

Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()

CVSS3: 6.5
debian
22 дня назад

A stack-based buffer overflow was found in rpcbind's rpcinfo utility. ...

CVSS3: 6.5
github
22 дня назад

A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcinfo -l`, address information returned by the server is copied into a fixed-size buffer without sufficient bounds checking. A malicious or compromised rpcbind server could use this flaw to crash the rpcinfo client, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

EPSS

Процентиль: 20%
0.00278
Низкий

6.5 Medium

CVSS3