Skip to content
Red HatCVE-2026-16277

Red Hat Enterprise Linux 10: stack buffer overflow

Medium6.5CVE-2026-16277 · Published Jul 20, 2026 · updated Jul 21, 2026

A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcinfo -l`, address information returned by the server is copied into a fixed-size buffer without sufficient bounds checking. A malicious or compromised rpcbind server could use this flaw to crash the rpcinfo client, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Red Hat OpenShift Container Platform 4
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat libcupsfilters: denial of service
High7.5Jul 20
Red Hat: path traversal
Critical9.0Jul 20
Red Hat Enterprise Linux 10: race condition
High7.3Jul 20
Red Hat claircore: denial of service
Medium4.3Jul 20
Red Hat: denial of service
Medium5.3Jul 20
Red Hat Enterprise Linux 10: out-of-bounds write
Medium6.5Jul 20

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.