Impact
A stack-based buffer overflow exists in the rpcinfo utility of rpcbind. In its short mode, accessed via the rpcinfo –s command, the client copies version numbers from a remote RPCBPROC_DUMP reply into a fixed-size stack buffer without bounds checking. When an attacker controls or compromises the rpcbind endpoint, this can corrupt the stack and crash the rpcinfo client, resulting in a denial of service. The vulnerability does not provide a path to remote code execution or data exfiltration.
Affected Systems
The flaw affects Red Hat Enterprise Linux 8, 9, and 10, as well as Red Hat OpenShift Container Platform 4. Any host running these operating system releases or platforms with an accessible rpcbind service can be impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate risk, while an EPSS score of less than 1 % suggests a low likelihood of exploitation at present. The vulnerability is not listed in CISA KEV. Exploitation requires a remote attacker to direct the rpcinfo utility at a malicious or compromised rpcbind instance, which is feasible over the network and would affect only the client side, causing a crash or denial of service.
OpenCVE Enrichment