CVE-2026-16461: Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting
A flaw was found in rpcbind's rpcinfo utility. In rpcbdump() short mode, used by rpcinfo -s, version values returned by a remote RPCBPROCDUMP reply are appended via unbounded sprintf() calls into a fixed 256-byte stack buffer without tracking remaining space:
c char buf[256]; char p = buf; for (vl = rs->vlist; vl; vl = vl->next) { sprintf (p, "%d", vl->vers); p = p + strlen (p); if (vl->next) sprintf (p++, ","); }
A malicious or compromised rpcbind endpoint that returns enough distinct version numbers for a single program (roughly 24 maximum-width decimal values plus separators) can overflow this buffer. A user or administrator must run rpcinfo -s <host> against the hostile endpoint; no privileges on the victim are required, but user interaction is needed. Current evidence supports client-side stack memory corruption leading to a crash/denial of service of the rpcinfo client process; disclosure or reliable code execution are not established.
This bug was originally reported bundled together with a related, since-fixed overflow in rpcbaddrlist() (now tracked separately as CVE-2026-16277). Confirmed via direct inspection of upstream commit bb9bb7286a4c345442946dc2ce3c9e7f67e96d4d (rpcbind 1.2.9) that this rpcbdump() short-mode overflow is NOT fixed by that commit and remains present in the latest upstream release.
Steps to reproduce: 1. Build rpcbind with AddressSanitizer: CFLAGS="-O1 -g -fsanitize=address -fno-omit-frame-pointer" ./configure && make -j 2. Run a malicious rpcbind-compatible endpoint, or an instrumented test responder. 3. Return an RPCBPROCDUMP list for one program with enough distinct versions (~24+ max-width decimal values) to exceed 256 bytes. 4. Run ./src/rpcinfo -s <attacker-host>. 5. Observe an ASan stack-buffer-overflow report or client crash.
Proposed fix (not yet applied upstream): convert the version-list formatter to bounded snprintf() calls that track remaining buffer space. diff char p = buf; +char p = buf; +sizet rem = sizeof(buf); +int n; +buf[0] = '\0'; for (vl = rs->vlist; vl; vl = vl->next) { - sprintf (p, "%d", vl->vers); - p = p + strlen (p); - if (vl->next) - sprintf (p++, ","); + n = snprintf(p, rem, "%d%s", vl->vers, vl->next ? "," : ""); + if (n < 0) + break; + if ((sizet)n >= rem) { + p = buf + sizeof(buf) - 1; + break; + } + p += n; + rem -= (sizet)n; }
Other sources
A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by rpcinfo -s), version numbers from a remote RPCBPROCDUMP reply are written into a fixed-size stack buffer without bounds checking. A user or administrator who runs rpcinfo -s against a malicious or compromised rpcbind endpoint could experience a crash or denial of service of the rpcinfo client.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16461?
The severity of CVE-2026-16461 is rated as medium with a score of 6.5.
What is CVE-2026-16461?
CVE-2026-16461 is a vulnerability in rpcbind's rpcinfo utility that allows for a stack buffer overflow due to improper bounds checking.
How does CVE-2026-16461 impact system security?
CVE-2026-16461 can be exploited by an attacker to cause denial of service by crashing the rpcinfo utility or potentially executing arbitrary code.
How do I fix CVE-2026-16461?
To fix CVE-2026-16461, update the rpcbind package to the latest version where the vulnerability has been patched.
Which software is affected by CVE-2026-16461?
CVE-2026-16461 affects the rpcbind software, specifically the rpcinfo utility in its rpcbdump() functionality.