CVE-2026-16461: Stack-based Buffer Overflow in Red Hat Red Hat Enterprise Linux 10
A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), version numbers from a remote RPCBPROC_DUMP reply are written into a fixed-size stack buffer without bounds checking. A user or administrator who runs `rpcinfo -s` against a malicious or compromised rpcbind endpoint could experience a crash or denial of service of the rpcinfo client.
AI Analysis
Technical Summary
A stack-based buffer overflow exists in the rpcinfo utility of rpcbind on Red Hat Enterprise Linux 10. Specifically, in the rpcbdump() short mode (triggered by `rpcinfo -s`), version numbers from a remote RPCBPROC_DUMP reply are copied into a fixed-size stack buffer without bounds checking. This lack of bounds validation can lead to a buffer overflow, causing the rpcinfo client to crash or deny service when interacting with a malicious or compromised rpcbind endpoint. The vulnerability is remotely exploitable without privileges and requires user interaction (running `rpcinfo -s`). The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, reflecting network attack vector, low attack complexity, no privileges required, user interaction required, unchanged scope, no confidentiality or integrity impact, and high availability impact. The vendor advisory does not currently specify a remediation or patch status.
Potential Impact
Successful exploitation results in a denial of service condition for the rpcinfo client due to a crash caused by a stack-based buffer overflow. There is no impact on confidentiality or integrity. The vulnerability requires a user or administrator to run `rpcinfo -s` against a malicious or compromised rpcbind endpoint, which could cause the client to crash and disrupt availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-16461 for current remediation guidance. Until a patch is available, avoid running `rpcinfo -s` against untrusted or potentially malicious rpcbind endpoints to prevent triggering the vulnerability.
CVE-2026-16461: Stack-based Buffer Overflow in Red Hat Red Hat Enterprise Linux 10
Description
A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), version numbers from a remote RPCBPROC_DUMP reply are written into a fixed-size stack buffer without bounds checking. A user or administrator who runs `rpcinfo -s` against a malicious or compromised rpcbind endpoint could experience a crash or denial of service of the rpcinfo client.
CVSS v3.1
Score 6.5medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A stack-based buffer overflow exists in the rpcinfo utility of rpcbind on Red Hat Enterprise Linux 10. Specifically, in the rpcbdump() short mode (triggered by `rpcinfo -s`), version numbers from a remote RPCBPROC_DUMP reply are copied into a fixed-size stack buffer without bounds checking. This lack of bounds validation can lead to a buffer overflow, causing the rpcinfo client to crash or deny service when interacting with a malicious or compromised rpcbind endpoint. The vulnerability is remotely exploitable without privileges and requires user interaction (running `rpcinfo -s`). The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, reflecting network attack vector, low attack complexity, no privileges required, user interaction required, unchanged scope, no confidentiality or integrity impact, and high availability impact. The vendor advisory does not currently specify a remediation or patch status.
Potential Impact
Successful exploitation results in a denial of service condition for the rpcinfo client due to a crash caused by a stack-based buffer overflow. There is no impact on confidentiality or integrity. The vulnerability requires a user or administrator to run `rpcinfo -s` against a malicious or compromised rpcbind endpoint, which could cause the client to crash and disrupt availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-16461 for current remediation guidance. Until a patch is available, avoid running `rpcinfo -s` against untrusted or potentially malicious rpcbind endpoints to prevent triggering the vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-07-21T11:33:40.142Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-16461","vendor":"Red Hat"}]
Threat ID: 6a5f622e2a4a8d598918bdd9
Added to database: 07/21/2026, 12:12:30 UTC
Last enriched: 07/21/2026, 12:27:14 UTC
Last updated: 07/21/2026, 21:20:00 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.