libtirpc: Infinite loop in EMFILE case in svc_vc.c
Published Aug 30, 2018
7.5
HIGHCVSS 3.0
EPSS 2.26%
Description
An infinite loop vulnerability was found in libtirpc before version 1.0.2-rc2. With the port to using poll rather than select, exhaustion of file descriptors would cause the server to enter an infinite loop, consuming a large amount of CPU time and denying service to other clients until restarted.
Affected products
- Vendor n/a Product Libtirpc Defaultn/a
- Version 1.0.2-rc2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Libtirpc | n/a |
|
- ≤ 1.0.1
- 1.0.2
No data.
Red Hat Ceph Storage 2
libntirpc
Not affected
Red Hat Ceph Storage 3
libntirpc
Not affected
Red Hat Enterprise Linux 6
libtirpc
Not affected
Red Hat Enterprise Linux 7
libtirpc
Not affected
Red Hat Enterprise Linux 8
libtirpc
Not affected
Red Hat OpenShift Enterprise 3
libtirpc
Not affected
Red Hat Storage 3
libntirpc
Not affected
Red Hat Virtualization 4
libtirpc
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ceph Storage 2 | libntirpc | Not affected | n/a |
| Red Hat Ceph Storage 3 | libntirpc | Not affected | n/a |
| Red Hat Enterprise Linux 6 | libtirpc | Not affected | n/a |
| Red Hat Enterprise Linux 7 | libtirpc | Not affected | n/a |
| Red Hat Enterprise Linux 8 | libtirpc | Not affected | n/a |
| Red Hat OpenShift Enterprise 3 | libtirpc | Not affected | n/a |
| Red Hat Storage 3 | libntirpc | Not affected | n/a |
| Red Hat Virtualization 4 | libtirpc | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- http://git.linux-nfs.org/?p=steved/libtirpc.git%3Ba=commit%3Bh=fce98161d9815ea016855d9f00274276452c2c4b x_refsource_CONFIRM
- https://access.redhat.com/security/cve/CVE-2018-14621 Vendor Advisory
- https://bugzilla.novell.com/show_bug.cgi?id=968175 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1620290 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14621 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-6528 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-14621
- https://www.cve.org/CVERecord?id=CVE-2018-14621
| Link | Providers | Tags |
|---|---|---|
| http://git.linux-nfs.org/?p=steved/libtirpc.git%3Ba=commit%3Bh=fce98161d9815ea016855d9f00274276452c2c4b | x_refsource_CONFIRM | |
| https://access.redhat.com/security/cve/CVE-2018-14621 | Vendor Advisory | |
| https://bugzilla.novell.com/show_bug.cgi?id=968175 | x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1620290 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14621 | x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-6528 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-14621 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-14621 |
Change history (0)
No recorded changes yet.