CVE-2026-16277

NameCVE-2026-16277
DescriptionA stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcinfo -l`, address information returned by the server is copied into a fixed-size buffer without sufficient bounds checking. A malicious or compromised rpcbind server could use this flaw to crash the rpcinfo client, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1142506

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rpcbind (PTS)bullseye1.2.5-9vulnerable
bookworm1.2.6-6vulnerable
forky, sid, trixie1.2.7-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
rpcbindsource(unstable)(unfixed)1142506

Notes

Fixed by: https://git.linux-nfs.org/?p=steved/rpcbind.git;a=commitdiff;h=bb9bb7286a4c345442946dc2ce3c9e7f67e96d4d (rpcbind-1_2_9)

Search for package or bug name: Reporting problems