Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via crafted packets, involving a PMAP_CALLIT code.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade rpcbind | Aug 30, 2017 | Oct 1, 2015 |
| Centos_linux | — | Upgrade rpcbind | Jul 6, 2016 | Oct 1, 2015 |
| Debian | — | Upgrade rpcbind | Jul 30, 2024 | Oct 1, 2015 |
| Freebsd | — | Upgrade FreeBSD | Dec 10, 2025 | Aug 11, 2016 |
| Gentoo Linux | — | Upgrade net-nds/rpcbind. | Oct 30, 2017 | Oct 1, 2015 |
| Oracle Solaris | — | Upgrade system/core-os to version 0.5.11-0.175.3.4.0.3.0 on Solaris 11.3 | May 29, 2017 | Oct 1, 2015 |
| Oracle_linux | — | Upgrade rpcbind | Oct 16, 2024 | Oct 1, 2015 |
| Suse | — | Upgrade rpcbind | Dec 18, 2015 | Oct 1, 2015 |
| Ubuntu | — | Upgrade rpcbind | Nov 8, 2024 | Oct 1, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub