Bug 2502719 (CVE-2026-16461)
| Summary: | CVE-2026-16461 rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | rhel-process-autobot, security-response-team, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), version numbers from a remote RPCBPROC_DUMP reply are written into a fixed-size stack buffer without bounds checking. A user or administrator who runs `rpcinfo -s` against a malicious or compromised rpcbind endpoint could experience a crash or denial of service of the rpcinfo client.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
A flaw was found in rpcbind's rpcinfo utility. In rpcbdump() short mode, used by `rpcinfo -s`, version values returned by a remote RPCBPROC_DUMP reply are appended via unbounded sprintf() calls into a fixed 256-byte stack buffer without tracking remaining space: ```c char buf[256]; char *p = buf; for (vl = rs->vlist; vl; vl = vl->next) { sprintf (p, "%d", vl->vers); p = p + strlen (p); if (vl->next) sprintf (p++, ","); } ``` A malicious or compromised rpcbind endpoint that returns enough distinct version numbers for a single program (roughly 24 maximum-width decimal values plus separators) can overflow this buffer. A user or administrator must run `rpcinfo -s <host>` against the hostile endpoint; no privileges on the victim are required, but user interaction is needed. Current evidence supports client-side stack memory corruption leading to a crash/denial of service of the `rpcinfo` client process; disclosure or reliable code execution are not established. This bug was originally reported bundled together with a related, since-fixed overflow in rpcbaddrlist() (now tracked separately as CVE-2026-16277). Confirmed via direct inspection of upstream commit bb9bb7286a4c345442946dc2ce3c9e7f67e96d4d (rpcbind 1.2.9) that this rpcbdump() short-mode overflow is NOT fixed by that commit and remains present in the latest upstream release. Steps to reproduce: 1. Build rpcbind with AddressSanitizer: `CFLAGS="-O1 -g -fsanitize=address -fno-omit-frame-pointer" ./configure && make -j` 2. Run a malicious rpcbind-compatible endpoint, or an instrumented test responder. 3. Return an RPCBPROC_DUMP list for one program with enough distinct versions (~24+ max-width decimal values) to exceed 256 bytes. 4. Run `./src/rpcinfo -s <attacker-host>`. 5. Observe an ASan stack-buffer-overflow report or client crash. Proposed fix (not yet applied upstream): convert the version-list formatter to bounded snprintf() calls that track remaining buffer space. ```diff char *p = buf; +char *p = buf; +size_t rem = sizeof(buf); +int n; +buf[0] = '\0'; for (vl = rs->vlist; vl; vl = vl->next) { - sprintf (p, "%d", vl->vers); - p = p + strlen (p); - if (vl->next) - sprintf (p++, ","); + n = snprintf(p, rem, "%d%s", vl->vers, vl->next ? "," : ""); + if (n < 0) + break; + if ((size_t)n >= rem) { + p = buf + sizeof(buf) - 1; + break; + } + p += n; + rem -= (size_t)n; } ```