Impact
The Linux kernel’s rpcb_register_inet4 and rpcb_register_inet6 functions store the result of rpc_sockaddr2uaddr() into map->r_addr without checking for NULL. When rpc_sockaddr2uaddr() fails to allocate memory, it returns NULL, and that null value can later be dereferenced during RPCBPROC_SET encoding, triggering a strlen on a NULL pointer and causing a kernel panic. The crash is visible as a general‑protection fault and results in an oops, effectively bringing the system down. No arbitrary code execution or privilege escalation is indicated – the flaw is a local denial‑of‑service condition tied to kernel memory allocation failures.
Affected Systems
All Linux kernel implementations that contain the rpcb_register_inet4/6 code path are potentially affected. The issue was demonstrated on kernel v6.12; older kernels using identical functions are also at risk, while there is no vendor‑specific version information available in the advisory, so any user of the generic Linux kernel that has not yet applied the fix could be impacted.
Risk and Exploitability
The vulnerability requires an in‑kernel RPC service (e.g., nfsd, lockd, nfs‑callback) to register with rpcbind while a memory allocation for rpc_sockaddr2uaddr() fails. This condition is local to the host and would likely need the attacker to induce memory pressure or otherwise trigger the failure path; it is not documented as remotely exploitable. The EPSS score is < 1%, indicating a very low likelihood of exploitation in the wild. The flaw is not listed in CISA KEV, which suggests limited public exploitation, but the impact of a kernel crash remains serious if the vulnerability is reached.
OpenCVE Enrichment
Debian DLA
Debian DSA