Status: UPDATED
| Advisory ID: CVE-2026-94640
Key Details
| CVE | CVE-2026-94640 |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-09-26 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high. |
| Affected products | see table below |
| Classified as | CWE-400 (Uncontrolled Resource Consumption) |
Affected Products, Subsystems & Sectors
| Subsystems | OT Supporting Infrastructure |
| Sectors | Multiple |
What to Know
A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a large number of unique requests. The rpcbind service records previously unseen RPC (Remote Procedure Call) statistics in unbounded in-memory lists, leading to persistent memory growth and increased CPU usage. This can degrade or exhaust service availability. (NVD)
What to Do
Monitor Red Hat's web page for any future patch releases.
References