REDHAT-BUG-2502719: Medium severity rpcbind vulnerability
A flaw was found in rpcbind's rpcinfo utility. In rpcbdump() short mode, used by rpcinfo -s, version values returned by a remote RPCBPROCDUMP reply are appended via unbounded sprintf() calls into a fixed 256-byte stack buffer without tracking remaining space:
c char buf[256]; char p = buf; for (vl = rs->vlist; vl; vl = vl->next) { sprintf (p, "%d", vl->vers); p = p + strlen (p); if (vl->next) sprintf (p++, ","); }
A malicious or compromised rpcbind endpoint that returns enough distinct version numbers for a single program (roughly 24 maximum-width decimal values plus separators) can overflow this buffer. A user or administrator must run rpcinfo -s <host> against the hostile endpoint; no privileges on the victim are required, but user interaction is needed. Current evidence supports client-side stack memory corruption leading to a crash/denial of service of the rpcinfo client process; disclosure or reliable code execution are not established.
This bug was originally reported bundled together with a related, since-fixed overflow in rpcbaddrlist() (now tracked separately as CVE-2026-16277). Confirmed via direct inspection of upstream commit bb9bb7286a4c345442946dc2ce3c9e7f67e96d4d (rpcbind 1.2.9) that this rpcbdump() short-mode overflow is NOT fixed by that commit and remains present in the latest upstream release.
Steps to reproduce: 1. Build rpcbind with AddressSanitizer: CFLAGS="-O1 -g -fsanitize=address -fno-omit-frame-pointer" ./configure && make -j 2. Run a malicious rpcbind-compatible endpoint, or an instrumented test responder. 3. Return an RPCBPROCDUMP list for one program with enough distinct versions (~24+ max-width decimal values) to exceed 256 bytes. 4. Run ./src/rpcinfo -s <attacker-host>. 5. Observe an ASan stack-buffer-overflow report or client crash.
Proposed fix (not yet applied upstream): convert the version-list formatter to bounded snprintf() calls that track remaining buffer space. diff char p = buf; +char p = buf; +sizet rem = sizeof(buf); +int n; +buf[0] = '\0'; for (vl = rs->vlist; vl; vl = vl->next) { - sprintf (p, "%d", vl->vers); - p = p + strlen (p); - if (vl->next) - sprintf (p++, ","); + n = snprintf(p, rem, "%d%s", vl->vers, vl->next ? "," : ""); + if (n < 0) + break; + if ((sizet)n >= rem) { + p = buf + sizeof(buf) - 1; + break; + } + p += n; + rem -= (sizet)n; }
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rpcbind (rpcinfo / rpcbdump short mode)to a version that resolves this vulnerability.Fixed in 1.2.9 - Configuration
In rpcbdump() short mode (used by `rpcinfo -s`), change the formatter code that currently does `sprintf(p++, ",")` and `sprintf(p, "%d", vl->vers)` into bounded `snprintf()` calls that track remaining space (`size_t rem = sizeof(buf)`). This is the proposed fix described in the material (not yet applied upstream).
rpcbind (rpcinfo utility / rpcbdump() short mode) Replace unbounded sprintf() with bounded snprintf() while tracking remaining buffer space in the version-list formatter = Use snprintf(p, rem, ...) and decrement `rem` after each append; keep `p` within the fixed `char buf[256]`. - Compensating control
Do not run `rpcinfo -s <host>` against untrusted or potentially malicious rpcbind endpoints; user interaction is required to trigger the client-side stack-buffer overflow.
- Compensating control
Mitigate by building rpcbind (including rpcinfo) with AddressSanitizer instrumentation using `CFLAGS="-O1 -g -fsanitize=address -fno-omit-frame-pointer" ./configure && make -j` to detect and prevent unnoticed stack-buffer-overflow exploitation during testing.
- Operational
After applying the proposed bounded-snprintf code change, reproduce and verify: (1) run `./src/rpcinfo -s <attacker-host>` against a malicious rpcbind-compatible endpoint (or instrumented responder) that returns enough distinct version numbers to overflow the 256-byte buffer; (2) confirm the client crash/stack-buffer-overflow no longer occurs (e.g., via ASan reports).
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2502719?
The severity of REDHAT-BUG-2502719 is classified as medium.
What type of vulnerability is REDHAT-BUG-2502719?
REDHAT-BUG-2502719 is a stack buffer overflow vulnerability in rpcbind's rpcinfo utility.
How do I fix REDHAT-BUG-2502719?
To fix REDHAT-BUG-2502719, update to the latest version of the rpcbind software that addresses this issue.
What software is affected by REDHAT-BUG-2502719?
The affected software in REDHAT-BUG-2502719 is rpcbind.
When was REDHAT-BUG-2502719 published?
REDHAT-BUG-2502719 was published on July 20, 2026.