[Git][security-tracker-team/security-tracker][master] Add CVE-2026-16277/rpcbind

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jul 20 22:10:01 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
87117677 by Salvatore Bonaccorso at 2026-07-20T23:08:46+02:00
Add CVE-2026-16277/rpcbind

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -291,7 +291,8 @@ CVE-2026-21824 (HCL Commerce contains an privilege escalation vulnerability that
 CVE-2026-16312
 	REJECTED
 CVE-2026-16277 (A stack-based buffer overflow was found in rpcbind's rpcinfo utility.  ...)
-	TODO: check
+	- rpcbind <unfixed>
+	NOTE: Fixed by: https://git.linux-nfs.org/?p=steved/rpcbind.git;a=commitdiff;h=bb9bb7286a4c345442946dc2ce3c9e7f67e96d4d (rpcbind-1_2_9)
 CVE-2026-16254 (A flaw was found in claircore's apk package scanner. Malformed package ...)
 	TODO: check
 CVE-2026-16252 (A security flaw has been discovered in Beijing Shenzhou Shihan Technol ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/87117677375ea429ba080e4edeb63166b633b15f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/87117677375ea429ba080e4edeb63166b633b15f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260720/f40f60fb/attachment.htm>


More information about the debian-security-tracker-commits mailing list