Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-93306.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-93306
Upstream
  • CVE-2026-16461
Published
2026-07-21T12:17:21Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-16461 affecting package rpcbind 1.2.9-1
Details

A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by rpcinfo -s), version numbers from a remote RPCBPROC_DUMP reply are written into a fixed-size stack buffer without bounds checking. A user or administrator who runs rpcinfo -s against a malicious or compromised rpcbind endpoint could experience a crash or denial of service of the rpcinfo client.

References

Affected packages

Azure Linux:3 / rpcbind

Package

Name
rpcbind
Purl
pkg:rpm/azure-linux/rpcbind

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.2.9-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-93306.json"