CVE-2017-8779: High severity Rpcbind Project Rpcbind vulnerability
Last updated 18 August 2025
Other sources
Rpcbind does not consider the maximum RPC data size during memory allocation for XDR strings, which allows remote attackers to cause a denial of service (memory consumption with no subsequent free) via a crafted UDP packet to port 111, aka rpcbomb.
References:
http://seclists.org/oss-sec/2017/q2/209 https://guidovranken.wordpress.com/2017/05/03/rpcbomb-remote-rpcbind-denial-of-service-patches/
— Red Hat
rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data size during memory allocation for XDR strings, which allows remote attackers to cause a denial of service (memory consumption with no subsequent free) via a crafted UDP packet to port 111, aka rpcbomb.
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8779?
CVE-2017-8779 has a high severity rating due to its potential to cause denial of service through excessive memory consumption.
How do I fix CVE-2017-8779?
To fix CVE-2017-8779, upgrade to the recommended versions of rpcbind, libtirpc, or ntirpc as specified in the vulnerability report.
What systems are affected by CVE-2017-8779?
CVE-2017-8779 affects versions of rpcbind up to 0.2.4, libtirpc up to 1.0.1, and ntirpc up to 1.4.3.
Can CVE-2017-8779 be exploited remotely?
Yes, CVE-2017-8779 can be exploited remotely via crafted UDP packets sent to port 111.
What is the potential impact of CVE-2017-8779 on servers?
The potential impact of CVE-2017-8779 on servers includes denial of service, leading to unavailability and potential downtime.