Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package rpcbind for openSUSE:Factory checked in at 2026-09-29 17:45:30 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/rpcbind (Old) and /work/SRC/openSUSE:Factory/.rpcbind.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "rpcbind" Tue Sep 29 17:45:30 2026 rev:75 rq:1380784 version:1.2.9 Changes: -------- --- /work/SRC/openSUSE:Factory/rpcbind/rpcbind.changes 2026-09-08 16:53:35.547644206 +0200 +++ /work/SRC/openSUSE:Factory/.rpcbind.new.383539/rpcbind.changes 2026-09-29 17:45:34.035648251 +0200 @@ -1,0 +2,7 @@ +Thu Sep 24 07:16:58 UTC 2026 - Thomas Blume <[email protected]> + +- Bound stats lists in rpcbs_getaddr() and rpcbs_rmtcall() + (bsc#1282326, CVE-2026-94640) + * add 0001-rpcbind-bound-stats-lists-in-rpcbs_getaddr-and-rpcbs.patch + +------------------------------------------------------------------- New: ---- 0001-rpcbind-bound-stats-lists-in-rpcbs_getaddr-and-rpcbs.patch ----------(New B)---------- New: (bsc#1282326, CVE-2026-94640) * add 0001-rpcbind-bound-stats-lists-in-rpcbs_getaddr-and-rpcbs.patch ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ rpcbind.spec ++++++ --- /var/tmp/diff_new_pack.eXHg02/_old 2026-09-29 17:45:35.190696598 +0200 +++ /var/tmp/diff_new_pack.eXHg02/_new 2026-09-29 17:45:35.192696681 +0200 @@ -31,7 +31,8 @@ Source: https://downloads.sourceforge.net/sourceforge/%{name}/%{name}-%{version}.tar.bz2 Source2: sysconfig.rpcbind Source5: rpc-user.conf -Patch: 0001-rpcinfo-fix-stack-buffer-overflow-in-rpcbdump-short-.patch +Patch1: 0001-rpcinfo-fix-stack-buffer-overflow-in-rpcbdump-short-.patch +Patch2: 0001-rpcbind-bound-stats-lists-in-rpcbs_getaddr-and-rpcbs.patch BuildRequires: libtirpc-devel >= 1.0.1 BuildRequires: libtool BuildRequires: pkgconfig ++++++ 0001-rpcbind-bound-stats-lists-in-rpcbs_getaddr-and-rpcbs.patch ++++++ >From 1aa8081440d6fd86729692d0d5604c3ff583656c Mon Sep 17 00:00:00 2001 From: Scott Mayhew <[email protected]> Date: Sat, 5 Sep 2026 14:11:49 -0400 Subject: [PATCH] rpcbind: bound stats lists in rpcbs_getaddr() and rpcbs_rmtcall() Limit addrinfo and rmtinfo linked lists to 4096 entries by trimming the oldest entries from the tail after prepending a new one. This prevents unbounded memory growth from a large number of unique program/version/netid combinations. Assisted-by: Claude:claude-opus-4-6 Signed-off-by: Scott Mayhew <[email protected]> Signed-off-by: Steve Dickson <[email protected]> --- src/rpcb_stat.c | 35 ++++++++++++++++++++++++++++++++--- 1 file changed, 32 insertions(+), 3 deletions(-) diff --git a/src/rpcb_stat.c b/src/rpcb_stat.c index 2e5226c..0799a47 100644 --- a/src/rpcb_stat.c +++ b/src/rpcb_stat.c @@ -50,6 +50,8 @@ #include <string.h> #include "rpcbind.h" +#define MAX_STAT_BUCKETS 4096 + static rpcb_stat_byvers inf; void @@ -104,8 +106,9 @@ void rpcbs_getaddr(rpcvers_t rtype, rpcprog_t prog, rpcvers_t vers, char *netid, char *uaddr) { - rpcbs_addrlist *al; + rpcbs_addrlist *al, *cut = NULL, *tmp; struct netconfig *nconf; + int listlen = 0; if (rtype >= RPCBVERS_STAT) return; @@ -121,6 +124,9 @@ rpcbs_getaddr(rpcvers_t rtype, rpcprog_t prog, rpcvers_t vers, char *netid, al->success++; return; } + listlen++; + if (listlen == MAX_STAT_BUCKETS - 1) + cut = al; } nconf = rpcbind_get_conf(netid); if (nconf == NULL) { @@ -142,14 +148,25 @@ rpcbs_getaddr(rpcvers_t rtype, rpcprog_t prog, rpcvers_t vers, char *netid, } al->next = inf[rtype].addrinfo; inf[rtype].addrinfo = al; + + if (cut) { + al = cut->next; + cut->next = NULL; + while (al) { + tmp = al; + al = al->next; + free(tmp); + } + } } void rpcbs_rmtcall(rpcvers_t rtype, rpcproc_t rpcbproc, rpcprog_t prog, rpcvers_t vers, rpcproc_t proc, char *netid, rpcblist_ptr rbl) { - rpcbs_rmtcalllist *rl; + rpcbs_rmtcalllist *rl, *cut = NULL, *tmp; struct netconfig *nconf; + int listlen = 0; if (rtype >= RPCBVERS_STAT) return; @@ -170,6 +187,9 @@ rpcbs_rmtcall(rpcvers_t rtype, rpcproc_t rpcbproc, rpcprog_t prog, rl->indirect++; return; } + listlen++; + if (listlen == MAX_STAT_BUCKETS - 1) + cut = rl; } nconf = rpcbind_get_conf(netid); if (nconf == NULL) { @@ -194,7 +214,16 @@ rpcbs_rmtcall(rpcvers_t rtype, rpcproc_t rpcbproc, rpcprog_t prog, rl->indirect = 1; rl->next = inf[rtype].rmtinfo; inf[rtype].rmtinfo = rl; - return; + + if (cut) { + rl = cut->next; + cut->next = NULL; + while (rl) { + tmp = rl; + rl = rl->next; + free(tmp); + } + } } void * -- 2.55.0
