AZL-105807

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105807.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-105807
Upstream
  • CVE-2026-94640
Published
2026-09-22T16:18:18Z
Modified
2026-10-03T14:16:42Z
Summary
CVE-2026-94640 affecting package rpcbind 1.2.9-1
Details

A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a large number of unique requests. The rpcbind service records previously unseen RPC (Remote Procedure Call) statistics in unbounded in-memory lists, leading to persistent memory growth and increased CPU usage. This can degrade or exhaust service availability.

References

Affected packages

Azure Linux:3 / rpcbind

Package

Name
rpcbind
Purl
pkg:rpm/azure-linux/rpcbind

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.2.9-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105807.json"