Executive brief
rpcbind is a service that manages RPC (Remote Procedure Call) connections on Unix and Linux systems. A remote attacker can send specially crafted requests to exhaust the server's memory and CPU, causing the service to become slow or unavailable. This denial of service requires no authentication and can be triggered over the network by any attacker.
Technical details
The vulnerability is an uncontrolled resource consumption flaw (CWE-400) in rpcbind's statistics tracking mechanism. When the service processes previously unseen RPC requests, it stores statistics in unbounded in-memory lists without proper resource limits, allowing an attacker to trigger persistent memory growth and CPU exhaustion via repeated unique requests sent over the network.
Affected products
- rpcbind
Timeline
- 2026-09-22: disclosed