CVE-2021-46828: High severity libtirpc vulnerability
Published Jul 20, 2022
·Updated
In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled. This can, in turn, lead to an svcrun infinite loop without accepting new connections.
Affected Software
5 affected componentsFixes available
debian/libtirpc<=1.3.2-2, <=1.1.4-0.4, <=1.3.1-1
1.3.2-2.11.3.1-1+deb11u1
debian/libtirpc<=1.1.4-0.4
1.1.4-0.4+deb10u11.3.1-1+deb11u11.3.3+ds-1
Libtirpc Project Libtirpc<1.3.3
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Remediation
Event History
Jul 20, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-46828?
CVE-2021-46828 is considered a high severity vulnerability due to its potential to exhaust file descriptors and cause denial of service.
2
How do I fix CVE-2021-46828?
To fix CVE-2021-46828, upgrade libtirpc to version 1.3.3rc1 or later.
3
Which versions of libtirpc are affected by CVE-2021-46828?
Versions of libtirpc prior to 1.3.3 are affected by CVE-2021-46828.
4
What can an attacker do with CVE-2021-46828?
An attacker can exploit CVE-2021-46828 to exhaust the file descriptors of a process using libtirpc, leading to a denial of service.
5
What systems are impacted by CVE-2021-46828?
Debian systems using libtirpc versions up to 1.3.2 are impacted by CVE-2021-46828.