{"id":"openSUSE-SU-2026:21019-1","summary":"Security update for rpcbind","details":"This update for rpcbind fixes the following issues\n\n- Update to rpcbind 1.2.9 (bsc#1267212)\n https://lore.kernel.org/linux-nfs/5cad3ab4-d24a-45fa-b1e9-d57b2c47a5e4@redhat.com/\n * rpcinfo: stack buffer overflow in rpcinfo rpcbaddrlist()\n * rpcbind: Stop unauthenticated oversized allocation in PMAPPROC_CALLIT decode\n * rpcbind: fix memory leak in read_warmstart()\n * rpcbind: fix memory leaks in network_init()\n * rpcbind: fix memory leak in init_transport()\n * Added -v (print version and compile flags)\n * rpcinfo: Removed a number of \"old-style function definition\" warnings\n * man/rpcbind: Update list of options\n * Comment out ListenStream=@/run/rpcbind.sock\n * [nfs/nfs-utils/rpcbind] rpcbind: avoid dereferencing NULL from realloc()\n * systemd/rpcbind.service.in: Add various hardenings options\n * man/rpcbind: Add Files section to manpage\n * Moved rpcbind.lock and default configs to /run instead of /var/run\n","modified":"2026-06-30T18:24:37.080284171Z","published":"2026-06-22T14:34:40Z","references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1117217"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181400"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267212"}],"affected":[{"package":{"name":"rpcbind","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/rpcbind&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.9-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"rpcbind":"1.2.9-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21019-1.json"}}],"schema_version":"1.7.5"}