CVE-2015-7236
published 2015-10-01CVE-2015-7236: Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2.1 and earlier allows remote attackers to cause a denial of service (daemon…
PriorityP340high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
6.41%
92.9th percentile
Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via crafted packets, involving a PMAP_CALLIT code.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | rpcbind | < rpcbind 0.2.1-6.1 (bookworm) | rpcbind 0.2.1-6.1 (bookworm) |
| oracle | solaris | — | — |
| oracle | solaris | — | — |
| rpcbind_project | rpcbind | <= 0.2.1 | — |
| rpcbind_project | rpcbind | >= 0 < 0.2.1-6.1 | 0.2.1-6.1 |
| rpcbind_project | rpcbind | >= 0 < 0.2.1-6.1 | 0.2.1-6.1 |
| rpcbind_project | rpcbind | >= 0 < 0.2.1-6.1 | 0.2.1-6.1 |
| rpcbind_project | rpcbind | >= 0 < 0.2.1-6.1 | 0.2.1-6.1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
rpcbind vulnerability
vendor_ubuntu·2015-09-30
CVE-2015-7236 rpcbind vulnerability
Title: rpcbind vulnerability
Summary: rpcbind could be made to crash or run programs if it received specially
crafted network traffic.
It was discovered that rpcbind incorrectly handled certain memory
structures. A remote attacker could use this issue to cause rpcbind to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
BSD
FreeBSD-SA-15:24.rpcbind: rpcbind(8) remote denial of service [REVISED]
bsd_advisories·2015-09-29·CVSS 7.5
CVE-2015-7236 [HIGH] FreeBSD-SA-15:24.rpcbind: rpcbind(8) remote denial of service [REVISED]
FreeBSD-SA-15:24.rpcbind Security Advisory
The FreeBSD Project
Topic: rpcbind(8) remote denial of service [REVISED]
Category: core
Module: rpcbind
Announced: 2015-09-29, revised on 2015-10-02
Affects: All supported versions of FreeBSD.
Corrected: 2015-10-02 16:36:16 UTC (stable/10, 10.2-STABLE)
2015-10-02 16:37:06 UTC (releng/10.2, 10.2-RELEASE-p5)
2015-10-02 16:37:06 UTC (releng/10.1, 10.1-RELEASE-p22)
2015-10-02 16:36:16 UTC (stable/9, 9.3-STABLE)
2015-10-02 16:37:06 UTC (releng/9.3, 9.3-RELEASE-p28)
CVE Name: CVE-2015-7236
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
0. Revision history
v1.0 2015-09-29 Initial release.
v1.1 2015-10-02 Revised patch to address
Red Hat
rpcbind: Use-after-free vulnerability in PMAP_CALLIT
vendor_redhat·2015-08-06·CVSS 7.5
CVE-2015-7236 [HIGH] CWE-416 rpcbind: Use-after-free vulnerability in PMAP_CALLIT
rpcbind: Use-after-free vulnerability in PMAP_CALLIT
Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via crafted packets, involving a PMAP_CALLIT code.
A use-after-free flaw related to the PMAP_CALLIT operation and TCP/UDP connections was discovered in rpcbind. A remote, unauthenticated attacker could possibly exploit this flaw to crash the rpcbind service (denial of service) by performing a series of UDP and TCP calls.
Debian
CVE-2015-7236: rpcbind - Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2...
vendor_debian·2015·CVSS 7.5
CVE-2015-7236 [HIGH] CVE-2015-7236: rpcbind - Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2...
Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via crafted packets, involving a PMAP_CALLIT code.
Scope: local
bookworm: resolved (fixed in 0.2.1-6.1)
bullseye: resolved (fixed in 0.2.1-6.1)
forky: resolved (fixed in 0.2.1-6.1)
sid: resolved (fixed in 0.2.1-6.1)
trixie: resolved (fixed in 0.2.1-6.1)
GHSA
GHSA-89q3-j7mw-8c8j: Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com
ghsa_unreviewed·2022-05-13
CVE-2015-7236 [HIGH] GHSA-89q3-j7mw-8c8j: Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com
Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via crafted packets, involving a PMAP_CALLIT code.
OSV
CVE-2015-7236: Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com
osv·2015-10-01·CVSS 7.5
CVE-2015-7236 [HIGH] CVE-2015-7236: Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com
Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via crafted packets, involving a PMAP_CALLIT code.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-7236 rpcbind: Use-after-free vulnerability in PMAP_CALLIT
bugzilla·2015-09-18·CVSS 7.5
CVE-2015-7236 [HIGH] CVE-2015-7236 rpcbind: Use-after-free vulnerability in PMAP_CALLIT
CVE-2015-7236 rpcbind: Use-after-free vulnerability in PMAP_CALLIT
A use-after-free vulnerability in rpcbind causing remotely triggerable crash was found. Rpcbind crashes in svc_dodestroy when trying to free a corrupted xprt->xp_netid pointer, which contains a sockaddr_in. Here's how it happens (as explained in http://www.spinics.net/lists/linux-nfs/msg53045.html ) :
- A PMAP_CALLIT call comes in on IPv4 UDP
- rpcbind duplicates the caller's address to a netbuf and stores
it in FINFO[0].caller_addr. caller_addr->buf now points to a
memory region A with a size of 16 bytes
- rpcbind forwards the call to the local service, receives a reply
- when processing the reply, it does this in xprt_set_caller:
xprt->xp_rtaddr = *FINFO[0].caller_addr
where xprt is the UDP transport on which it rece
Bugzilla
CVE-2015-7236 rpcbind: Use-after-free vulnerability in PMAP_CALLIT [fedora-all]
bugzilla·2015-09-18·CVSS 7.5
CVE-2015-7236 [HIGH] CVE-2015-7236 rpcbind: Use-after-free vulnerability in PMAP_CALLIT [fedora-all]
CVE-2015-7236 rpcbind: Use-after-free vulnerability in PMAP_CALLIT [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions o
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171030.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172152.htmlhttp://www.debian.org/security/2015/dsa-3366http://www.openwall.com/lists/oss-security/2015/09/17/1http://www.openwall.com/lists/oss-security/2015/09/17/6http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/76771http://www.securitytracker.com/id/1033673http://www.spinics.net/lists/linux-nfs/msg53045.htmlhttp://www.ubuntu.com/usn/USN-2756-1https://security.FreeBSD.org/advisories/FreeBSD-SA-15:24.rpcbind.aschttps://security.gentoo.org/glsa/201611-17http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171030.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172152.htmlhttp://www.debian.org/security/2015/dsa-3366http://www.openwall.com/lists/oss-security/2015/09/17/1http://www.openwall.com/lists/oss-security/2015/09/17/6http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/76771http://www.securitytracker.com/id/1033673http://www.spinics.net/lists/linux-nfs/msg53045.htmlhttp://www.ubuntu.com/usn/USN-2756-1https://security.FreeBSD.org/advisories/FreeBSD-SA-15:24.rpcbind.aschttps://security.gentoo.org/glsa/201611-17
2015-10-01
Published