SUSE alert openSUSE-SU-2026:21019-1 (rpcbind)
| From: | null@suse.de | |
| To: | security-announce@lists.opensuse.org | |
| Subject: | openSUSE-SU-2026:21019-1: moderate: Security update for rpcbind | |
| Date: | Tue, 30 Jun 2026 09:47:57 +0200 | |
| Message-ID: | <20260630074757.40F0CFF22@maintenance.suse.de> | |
| Archive-link: | Article |
openSUSE security update: security update for rpcbind ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21019-1 Rating: moderate References: * bsc#1117217 * bsc#1181400 * bsc#1267212 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that has 3 bug fixes can now be installed. Description: This update for rpcbind fixes the following issues - Update to rpcbind 1.2.9 (bsc#1267212) https://lore.kernel.org/linux-nfs/5cad3ab4-d24a-45fa-b1e9... * rpcinfo: stack buffer overflow in rpcinfo rpcbaddrlist() * rpcbind: Stop unauthenticated oversized allocation in PMAPPROC_CALLIT decode * rpcbind: fix memory leak in read_warmstart() * rpcbind: fix memory leaks in network_init() * rpcbind: fix memory leak in init_transport() * Added -v (print version and compile flags) * rpcinfo: Removed a number of "old-style function definition" warnings * man/rpcbind: Update list of options * Comment out ListenStream=@/run/rpcbind.sock * [nfs/nfs-utils/rpcbind] rpcbind: avoid dereferencing NULL from realloc() * systemd/rpcbind.service.in: Add various hardenings options * man/rpcbind: Add Files section to manpage * Moved rpcbind.lock and default configs to /run instead of /var/run Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1031=1 Package List: - openSUSE Leap 16.0: rpcbind-1.2.9-160000.1.1
