Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HFreebsd
OSFreebsd≤ 4.6.1Microsoft Windows 2000
OSMicrosoftall versionsMicrosoft Windows Nt
OSMicrosoft4.0Microsoft Windows Xp
OSMicrosoftall versionsOpenbsd
OSOpenbsd3.1Sun Solaris
OSSun2.69.0Sun Sunos
OSSun5.5.15.75.8
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
References
Related vulnerabilities
CVE-2014-1776CRITICAL9.8⚠ KEVPL ✓same product
Use-after-free w Microsoft Internet Explorer 6–11 umożliwia RCE
CVE-2008-4250CRITICAL9.8⚠ KEVPL ✓same product
RCE w usłudze Server systemu Windows przez przepełnienie bufora w RPC
CVE-2026-58081CRITICAL9.8same product
Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-sup...
CVE-2026-58082CRITICAL9.8same product
The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX (6 bytes) for intermediate character outp...
CVE-2024-10934CRITICAL9.2PL ✓same product
Double free i niezainicjowana zmienna w implementacji NFS systemu OpenBSD