CVE-2026-94640

Public on 2026-09-22
Modified on 2026-09-23
Description
A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a large number of unique requests. The rpcbind service records previously unseen RPC (Remote Procedure Call) statistics in unbounded in-memory lists, leading to persistent memory growth and increased CPU usage. This can degrade or exhaust service availability.
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
7.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core bind Not Affected
Amazon Linux 2023 bind Not Affected
Amazon Linux 2027 Preview bind Not Affected
Amazon Linux 2 - Core rpcbind Pending Fix
Amazon Linux 2023 rpcbind Pending Fix
Amazon Linux 2027 Preview rpcbind Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H