High severity7.5NVD Advisory· Published Oct 1, 2015· Updated Jun 17, 2026
CVE-2015-7236
CVE-2015-7236
Description
Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via crafted packets, involving a PMAP_CALLIT code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
19cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:*
- cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*
- osv-coords11 versionspkg:rpm/opensuse/rpcbind&distro=openSUSE%20Tumbleweedpkg:rpm/suse/rpcbind&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP3pkg:rpm/suse/rpcbind&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP4pkg:rpm/suse/rpcbind&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/rpcbind&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3pkg:rpm/suse/rpcbind&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATApkg:rpm/suse/rpcbind&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/rpcbind&distro=SUSE%20Linux%20Enterprise%20Server%2012pkg:rpm/suse/rpcbind&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP3pkg:rpm/suse/rpcbind&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/rpcbind&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012
< 0.2.3-7.1+ 10 more
- (no CPE)range: < 0.2.3-7.1
- (no CPE)range: < 0.1.6+git20080930-6.24.1
- (no CPE)range: < 0.1.6+git20080930-6.24.1
- (no CPE)range: < 0.2.1_rc4-13.3.1
- (no CPE)range: < 0.1.6+git20080930-6.24.1
- (no CPE)range: < 0.1.6+git20080930-6.24.1
- (no CPE)range: < 0.1.6+git20080930-6.24.1
- (no CPE)range: < 0.2.1_rc4-13.3.1
- (no CPE)range: < 0.1.6+git20080930-6.24.1
- (no CPE)range: < 0.1.6+git20080930-6.24.1
- (no CPE)range: < 0.2.1_rc4-13.3.1
Patches
Vulnerability mechanics
References
13- lists.fedoraproject.org/pipermail/package-announce/2015-November/171030.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2015-November/172152.htmlnvd
- www.debian.org/security/2015/dsa-3366nvd
- www.openwall.com/lists/oss-security/2015/09/17/1nvd
- www.openwall.com/lists/oss-security/2015/09/17/6nvd
- www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlnvd
- www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlnvd
- www.securityfocus.com/bid/76771nvd
- www.securitytracker.com/id/1033673nvd
- www.spinics.net/lists/linux-nfs/msg53045.htmlnvd
- www.ubuntu.com/usn/USN-2756-1nvd
- security.freebsd.org/advisories/FreeBSD-SA-15:24.rpcbind.ascnvd
- security.gentoo.org/glsa/201611-17nvd
News mentions
0No linked articles in our index yet.