Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-46828


In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled. This can, in turn, lead to an svc_run infinite loop without accepting new connections.


Published

2022-07-20T06:15:07.907

Last Modified

2025-05-05T17:17:29.090

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-755
    CWE-835
  • Type: Secondary
    CWE-755

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application libtirpc_project libtirpc < 1.3.3 Yes
Operating System debian debian_linux 10.0 Yes
Operating System debian debian_linux 11.0 Yes

References