Opened 4 months ago
Closed 4 months ago
#23370 closed enhancement (fixed)
rpcbind-1.2.9 (Security release)
| Reported by: | Bruce Dubbs | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | elevated | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (5)
comment:1 by , 4 months ago
| Priority: | normal → elevated |
|---|
comment:2 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:3 by , 4 months ago
| Summary: | rpcbind-1.2.9 → rpcbind-1.2.9 (Security release) |
|---|
Commits from https://git.linux-nfs.org/?p=steved/rpcbind.git since the last release:
Release: 1.2.9
- rpcinfo: stack buffer overflow in rpcinfo rpcbaddrlist()
- rpcbind: Stop unauthenticated oversized allocation...
- rpcbind: fix memory leak in read_warmstart()
- rpcbind: fix memory leaks in network_init()
- rpcbind: fix memory leak in init_transport()
comment:4 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
Fixed at commit 8a53e2eacb. Leaving open for SA.
Note:
See TracTickets
for help on using tickets.

Yeouch.
rpcinfo: stack buffer overflow in rpcinfo rpcbaddrlist() rpcinfo's rpcbaddrlist() formats two server-controlled, unbounded XDR strings into a fixed 128-byte stack buffer with sprintf(). A malicious or on-path rpcbind server overflows it when a user runs: rpcinfo -l <host> <prognum> <versnum>There are also memory leak fixes in here, but "rpcbind: Stop unauthenticated oversized allocation in PMAPPROC_CALLIT decode" is also notable.