CVE-2018-14621: High severity libtirpc vulnerability
An infinite loop vulnerability was found in libtirpc before version 1.0.2-rc2. With the port to using poll rather than select, exhaustion of file descriptors would cause the server to enter an infinite loop, consuming a large amount of CPU time and denying service to other clients until restarted.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-14621?
CVE-2018-14621 has a moderate severity rating due to its potential to cause denial of service through an infinite loop.
How do I fix CVE-2018-14621?
To fix CVE-2018-14621, upgrade libtirpc to version 1.0.2-rc2 or later.
What software versions are affected by CVE-2018-14621?
CVE-2018-14621 affects libtirpc versions prior to 1.0.2-rc2, including 1.0.1 and 1.0.2-rc1.
What are the consequences of CVE-2018-14621?
The consequences of CVE-2018-14621 include excessive CPU usage and denial of service to clients.
Is CVE-2018-14621 exploitable remotely?
CVE-2018-14621 is not specified as remotely exploitable, but can affect accessibility to services on the server.