CVE-2026-16277
Description
A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcinfo -l`, address information returned by the server is copied into a fixed-size buffer without sufficient bounds checking. A malicious or compromised rpcbind server could use this flaw to crash the rpcinfo client, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
How to fix CVE-2026-16277
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/rpcbind—no fix listed
Is CVE-2026-16277 being exploited?
No exploitation signal available. Neither CISA KEV nor a current EPSS score has been published for CVE-2026-16277.
Affected packages (1)
- from 0