https://seclists.org/oss-sec/2026/q3/228: CVE-2026-16277 & CVE-2026-16461: buffer overflows in rpcinfo
Published Jul 23, 2026
·Updated
Affected Software
3 affected components
Oracle ONC RPC (rpcinfo) / Sun NFS
NetBSD rpcinfo
illumos rpcinfo
Frequently Asked Questions
1
What is the severity of CVE-2026-16277 and CVE-2026-16461?
CVE-2026-16277 and CVE-2026-16461 are classified as high severity vulnerabilities due to the potential for remote code execution.
2
How do I fix CVE-2026-16277 and CVE-2026-16461?
To fix CVE-2026-16277 and CVE-2026-16461, update your Oracle ONC RPC, Sun NFS, or NetBSD rpcinfo software to the latest patched versions.
3
What systems are affected by CVE-2026-16277 and CVE-2026-16461?
CVE-2026-16277 and CVE-2026-16461 affect Oracle ONC RPC, Sun NFS, NetBSD rpcinfo, and illumos rpcinfo implementations.
4
What vulnerabilities are exploited in CVE-2026-16277 and CVE-2026-16461?
CVE-2026-16277 and CVE-2026-16461 exploit buffer overflow vulnerabilities when parsing and printing information from remote RPC calls.
5
When were CVE-2026-16277 and CVE-2026-16461 disclosed?
CVE-2026-16277 and CVE-2026-16461 were disclosed on July 23, 2026.