{"id":"AZL-105807","summary":"CVE-2026-94640 affecting package rpcbind 1.2.9-1","details":"A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a large number of unique requests. The rpcbind service records previously unseen RPC (Remote Procedure Call) statistics in unbounded in-memory lists, leading to persistent memory growth and increased CPU usage. This can degrade or exhaust service availability.","modified":"2026-10-04T05:34:07Z","published":"2026-09-22T16:18:18Z","upstream":["CVE-2026-94640"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94640"}],"affected":[{"package":{"name":"rpcbind","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/rpcbind"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.2.9-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105807.json"}}],"schema_version":"1.9.0"}