Impact
The vulnerability arises from unbounded in‑memory list allocation during rpcbind statistics tracking. An attacker can send many unique RPC requests over port 111, causing rpcbind to grow state information indefinitely. The resulting memory growth and CPU usage can degrade or exhaust service availability, leading to a denial of service for any client that relies on rpcbind. This flaw is classified under CWE-400, indicating excessive resource consumption.
Affected Systems
Affected vendors and products include multiple Red Hat distributions, specifically Red Enterprise Linux versions 6 through 10, and Red Hat OpenShift Container Platform 4. No specific patch version is listed in the data; the vulnerability is present in all highlighted releases.
Risk and Exploitability
The CVSS score of 7.5 reflects a moderate to high severity. No EPSS score is available. Because the flaw permits unauthenticated remote denial of service via port 111, an attacker with network reach to a vulnerable host can trigger it without additional credentials or privilege escalation. The vulnerability is not currently listed in CISA’s KEV catalog, but the lack of a release date means that the exploitation potential remains high until a patch or configuration change is applied.
OpenCVE Enrichment