Per discussion on the libc-alpha mailing list (linked https://sourceware.org/bugzilla/show_bug.cgi?id=21461#c7), this is an application vulnerability rather than a flaw in glibc. Users of the sunrpc library routines must be careful to use XDR_FREE, even when deserialisation failure occurs.