libntirpc: Memory leak when failing to parse XDR strings or bytearrays
Published May 4, 2017
7.5
HIGHCVSS 3.0
EPSS 81.23%
Description
rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data size during memory allocation for XDR strings, which allows remote attackers to cause a denial of service (memory consumption with no subsequent free) via a crafted UDP packet to port 111, aka rpcbomb.
Affected products
No data.
Configuration 1
- ≤ 0.2.4
Configuration 2
- ≤ 1.0.1
Configuration 3
- ≤ 1.4.3
No data.
Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7
calamari-server-0:1.5.6-2.el7cp
Fixed · RHBA-2017:1497
Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7
ceph-1:10.2.7-27.el7cp
Fixed · RHBA-2017:1497
Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7
ceph-iscsi-cli-0:2.0-5.el7cp
Fixed · RHBA-2017:1497
Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7
ceph-iscsi-config-0:2.0-4.el7cp
Fixed · RHBA-2017:1497
Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7
ceph-iscsi-tools-0:2.0-3.el7cp
Fixed · RHBA-2017:1497
Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7
libntirpc-0:1.4.3-2.el7
Fixed · RHBA-2017:1497
Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7
nfs-ganesha-0:2.4.5-7.el7cp
Fixed · RHBA-2017:1497
Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7
pcp-pmda-lio-0:1.0-2.el7cp
Fixed · RHBA-2017:1497
Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7
python-crypto-0:2.6.1-1.2.el7cp
Fixed · RHBA-2017:1497
Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7
python-flask-1:0.10.1-5.el7
Fixed · RHBA-2017:1497
Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7
python-itsdangerous-0:0.23-1.el7
Fixed · RHBA-2017:1497
Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7
python-jinja2-0:2.7.2-2.el7cp
Fixed · RHBA-2017:1497
Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7
python-rtslib-0:2.1.fb64-0.1.20170301.git3637171.el7cp
Fixed · RHBA-2017:1497
Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7
python-werkzeug-0:0.9.1-1.el7
Fixed · RHBA-2017:1497
Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7
targetcli-0:2.1.fb47-0.1.20170301.gitf632f38.el7cp
Fixed · RHBA-2017:1497
Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7
tcmu-runner-0:1.2.1-0.2.20170104.git3d33566.el7cp
Fixed · RHBA-2017:1497
Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7
userspace-rcu-0:0.7.16-1.el7cp
Fixed · RHBA-2017:1497
Red Hat Enterprise Linux 6
libtirpc-0:0.2.1-13.el6_9
Fixed · RHSA-2017:1268
Red Hat Enterprise Linux 6
rpcbind-0:0.2.0-13.el6_9
Fixed · RHSA-2017:1267
Red Hat Enterprise Linux 7
libtirpc-0:0.2.4-0.8.el7_3
Fixed · RHSA-2017:1263
Red Hat Enterprise Linux 7
rpcbind-0:0.2.0-38.el7_3
Fixed · RHSA-2017:1262
Red Hat Gluster Storage 3.2 for RHEL 6
libntirpc-0:1.4.3-4.el6rhs
Fixed · RHSA-2017:1395
Red Hat Gluster Storage 3.2 for RHEL 7
libntirpc-0:1.4.3-4.el7rhgs
Fixed · RHSA-2017:1395
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7 | calamari-server-0:1.5.6-2.el7cp | Fixed | RHBA-2017:1497 |
| Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7 | ceph-1:10.2.7-27.el7cp | Fixed | RHBA-2017:1497 |
| Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7 | ceph-iscsi-cli-0:2.0-5.el7cp | Fixed | RHBA-2017:1497 |
| Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7 | ceph-iscsi-config-0:2.0-4.el7cp | Fixed | RHBA-2017:1497 |
| Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7 | ceph-iscsi-tools-0:2.0-3.el7cp | Fixed | RHBA-2017:1497 |
| Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7 | libntirpc-0:1.4.3-2.el7 | Fixed | RHBA-2017:1497 |
| Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7 | nfs-ganesha-0:2.4.5-7.el7cp | Fixed | RHBA-2017:1497 |
| Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7 | pcp-pmda-lio-0:1.0-2.el7cp | Fixed | RHBA-2017:1497 |
| Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7 | python-crypto-0:2.6.1-1.2.el7cp | Fixed | RHBA-2017:1497 |
| Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7 | python-flask-1:0.10.1-5.el7 | Fixed | RHBA-2017:1497 |
| Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7 | python-itsdangerous-0:0.23-1.el7 | Fixed | RHBA-2017:1497 |
| Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7 | python-jinja2-0:2.7.2-2.el7cp | Fixed | RHBA-2017:1497 |
| Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7 | python-rtslib-0:2.1.fb64-0.1.20170301.git3637171.el7cp | Fixed | RHBA-2017:1497 |
| Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7 | python-werkzeug-0:0.9.1-1.el7 | Fixed | RHBA-2017:1497 |
| Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7 | targetcli-0:2.1.fb47-0.1.20170301.gitf632f38.el7cp | Fixed | RHBA-2017:1497 |
| Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7 | tcmu-runner-0:1.2.1-0.2.20170104.git3d33566.el7cp | Fixed | RHBA-2017:1497 |
| Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7 | userspace-rcu-0:0.7.16-1.el7cp | Fixed | RHBA-2017:1497 |
| Red Hat Enterprise Linux 6 | libtirpc-0:0.2.1-13.el6_9 | Fixed | RHSA-2017:1268 |
| Red Hat Enterprise Linux 6 | rpcbind-0:0.2.0-13.el6_9 | Fixed | RHSA-2017:1267 |
| Red Hat Enterprise Linux 7 | libtirpc-0:0.2.4-0.8.el7_3 | Fixed | RHSA-2017:1263 |
| Red Hat Enterprise Linux 7 | rpcbind-0:0.2.0-38.el7_3 | Fixed | RHSA-2017:1262 |
| Red Hat Gluster Storage 3.2 for RHEL 6 | libntirpc-0:1.4.3-4.el6rhs | Fixed | RHSA-2017:1395 |
| Red Hat Gluster Storage 3.2 for RHEL 7 | libntirpc-0:1.4.3-4.el7rhgs | Fixed | RHSA-2017:1395 |
No package ranges for this CVE.
Remediation
Red Hat statement
In the default system configuration, with the sysctl variable vm.overcommit_memory set to either 0 (the default) or 1, an attack would take a not-insignificant amount of time to exhaust the system's memory. If vm.overcommit_memory is set to a value of 2, the time required to exhaust system memory is sufficiently reduced. It was further noticed that, a 32-bit system would have its memory exhausted faster than a 64-bit system.
Red Hat mitigation
rpcbind should be protected by iptables so that only trusted hosts that require access can reach it (eg, nfs clients). Applying per-IP rate limits in iptables will also significantly limit the impact of this attack. The default iptables rules in the system-config-firewall or firewalld package deny all remote access to rpcbind. If you elect to run your system with overcommit turned off, daemons should have memory limits enforced by the init system to ensure stability. With systemd, use directives such as LimitAS in unit files. With upstart, place ulimit commands in /etc/sysconfig/$daemon.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AV:N/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (51 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 81.23% (0.81230) | 99.63th | v5 (v2026.06.15) |
| Sep 22, 2026 | 81.23% (0.81230) | 99.62th | v5 (v2026.06.15) |
| Sep 21, 2026 | 80.08% (0.80083) | 99.61th | v5 (v2026.06.15) |
| Sep 6, 2026 | 81.23% (0.81230) | 99.61th | v5 (v2026.06.15) |
| Sep 5, 2026 | 80.08% (0.80083) | 99.60th | v5 (v2026.06.15) |
| Aug 30, 2026 | 81.23% (0.81230) | 99.61th | v5 (v2026.06.15) |
| Aug 28, 2026 | 80.08% (0.80083) | 99.59th | v5 (v2026.06.15) |
| Aug 24, 2026 | 81.23% (0.81230) | 99.61th | v5 (v2026.06.15) |
| Aug 23, 2026 | 80.08% (0.80083) | 99.60th | v5 (v2026.06.15) |
| Jun 15, 2026 | 81.92% (0.81921) | 99.61th | v5 (v2026.06.15) |
| Mar 17, 2026 | 81.38% (0.81381) | 99.16th | v4 (v2025.03.14) |
| Mar 4, 2026 | 82.54% (0.82537) | 99.21th | v4 (v2025.03.14) |
| Mar 1, 2026 | 79.49% (0.79486) | 99.06th | v4 (v2025.03.14) |
| Feb 4, 2026 | 82.54% (0.82537) | 99.21th | v4 (v2025.03.14) |
| Feb 1, 2026 | 79.49% (0.79486) | 99.05th | v4 (v2025.03.14) |
| Jan 4, 2026 | 82.54% (0.82537) | 99.20th | v4 (v2025.03.14) |
| Jan 1, 2026 | 79.49% (0.79486) | 99.05th | v4 (v2025.03.14) |
| Dec 26, 2025 | 82.54% (0.82537) | 99.19th | v4 (v2025.03.14) |
| Dec 20, 2025 | 81.37% (0.81372) | 99.13th | v4 (v2025.03.14) |
| Dec 18, 2025 | 83.97% (0.83973) | 99.26th | v4 (v2025.03.14) |
| Dec 6, 2025 | 81.37% (0.81372) | 99.12th | v4 (v2025.03.14) |
| Dec 2, 2025 | 83.91% (0.83908) | 99.26th | v4 (v2025.03.14) |
| Dec 1, 2025 | 81.41% (0.81412) | 99.13th | v4 (v2025.03.14) |
| Nov 21, 2025 | 83.23% (0.83225) | 99.22th | v4 (v2025.03.14) |
| Nov 18, 2025 | 78.68% (0.78684) | 99.12th | v4 (v2025.03.14) |
| Nov 4, 2025 | 84.20% (0.84199) | 99.26th | v4 (v2025.03.14) |
| Nov 1, 2025 | 82.03% (0.82027) | 99.17th | v4 (v2025.03.14) |
| Oct 4, 2025 | 84.20% (0.84199) | 99.27th | v4 (v2025.03.14) |
| Oct 1, 2025 | 82.03% (0.82027) | 99.17th | v4 (v2025.03.14) |
| Sep 4, 2025 | 84.20% (0.84199) | 99.27th | v4 (v2025.03.14) |
| Sep 1, 2025 | 82.03% (0.82027) | 99.18th | v4 (v2025.03.14) |
| Aug 4, 2025 | 84.20% (0.84199) | 99.26th | v4 (v2025.03.14) |
| Aug 1, 2025 | 82.03% (0.82027) | 99.16th | v4 (v2025.03.14) |
| Jul 4, 2025 | 84.20% (0.84199) | 99.25th | v4 (v2025.03.14) |
| Jul 1, 2025 | 82.03% (0.82027) | 99.16th | v4 (v2025.03.14) |
| Jun 4, 2025 | 84.20% (0.84199) | 99.25th | v4 (v2025.03.14) |
| Jun 1, 2025 | 82.03% (0.82027) | 99.16th | v4 (v2025.03.14) |
| May 4, 2025 | 84.20% (0.84199) | 99.24th | v4 (v2025.03.14) |
| May 1, 2025 | 82.03% (0.82027) | 99.15th | v4 (v2025.03.14) |
| Mar 17, 2025 | 85.18% (0.85183) | 99.31th | v4 (v2025.03.14) |
| Dec 17, 2024 | 82.25% (0.82245) | 98.62th | v3 (v2023.03.01) |
| Nov 16, 2024 | 52.15% (0.52150) | 97.67th | v3 (v2023.03.01) |
| Aug 8, 2023 | 55.10% (0.55100) | 97.17th | v3 (v2023.03.01) |
| May 20, 2023 | 53.01% (0.53005) | 97.07th | v3 (v2023.03.01) |
| May 8, 2023 | 51.11% (0.51110) | 97.00th | v3 (v2023.03.01) |
| Mar 7, 2023 | 42.09% (0.42094) | 96.70th | v3 (v2023.03.01) |
| Mar 6, 2023 | 76.84% (0.76838) | 99.40th | v2 (v2022.01.01) |
| Feb 4, 2022 | 76.84% (0.76838) | 99.27th | v2 (v2022.01.01) |
| Feb 3, 2022 | 68.84% (0.68841) | 99.46th | v1 |
| Sep 1, 2021 | 68.84% (0.68841) | 99.83th | v1 |
| Apr 14, 2021 | 68.84% (0.68841) | 0.00th | v1 |
References (24)
- http://openwall.com/lists/oss-security/2017/05/03/12 x_refsource_MISCMailing ListPatchThird Party Advisory
- http://openwall.com/lists/oss-security/2017/05/04/1 x_refsource_MISCMailing ListPatchThird Party Advisory
- http://www.debian.org/security/2017/dsa-3845 vendor-advisoryx_refsource_DEBIAN
- http://www.securityfocus.com/bid/98325 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038532 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/errata/RHBA-2017:1497 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2017:1262 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2017:1263 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2017:1267 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2017:1268 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2017:1395 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2017-8779 Vendor Advisory
- https://access.redhat.com/solutions/3025811/
- https://bugzilla.redhat.com/show_bug.cgi?id=1448124 Issue Tracking
- https://github.com/drbothen/GO-RPCBOMB x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://github.com/guidovranken/rpcbomb/ x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://guidovranken.wordpress.com/2017/05/03/rpcbomb-remote-rpcbind-denial-of-service-patches/ x_refsource_MISCThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-8779
- https://security.gentoo.org/glsa/201706-07 vendor-advisoryx_refsource_GENTOO
- https://security.netapp.com/advisory/ntap-20180109-0001/ x_refsource_CONFIRM
- https://usn.ubuntu.com/3759-1/ vendor-advisoryx_refsource_UBUNTU
- https://usn.ubuntu.com/3759-2/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2017-8779
- https://www.exploit-db.com/exploits/41974/ exploitx_refsource_EXPLOIT-DB
Change history (0)
No recorded changes yet.