Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package rpcbind for openSUSE:Factory checked 
in at 2026-09-29 17:45:30
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/rpcbind (Old)
 and      /work/SRC/openSUSE:Factory/.rpcbind.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "rpcbind"

Tue Sep 29 17:45:30 2026 rev:75 rq:1380784 version:1.2.9

Changes:
--------
--- /work/SRC/openSUSE:Factory/rpcbind/rpcbind.changes  2026-09-08 
16:53:35.547644206 +0200
+++ /work/SRC/openSUSE:Factory/.rpcbind.new.383539/rpcbind.changes      
2026-09-29 17:45:34.035648251 +0200
@@ -1,0 +2,7 @@
+Thu Sep 24 07:16:58 UTC 2026 - Thomas Blume <[email protected]>
+
+- Bound stats lists in rpcbs_getaddr() and rpcbs_rmtcall()
+  (bsc#1282326, CVE-2026-94640)
+  * add 0001-rpcbind-bound-stats-lists-in-rpcbs_getaddr-and-rpcbs.patch
+
+-------------------------------------------------------------------

New:
----
  0001-rpcbind-bound-stats-lists-in-rpcbs_getaddr-and-rpcbs.patch

----------(New B)----------
  New:  (bsc#1282326, CVE-2026-94640)
  * add 0001-rpcbind-bound-stats-lists-in-rpcbs_getaddr-and-rpcbs.patch
----------(New E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ rpcbind.spec ++++++
--- /var/tmp/diff_new_pack.eXHg02/_old  2026-09-29 17:45:35.190696598 +0200
+++ /var/tmp/diff_new_pack.eXHg02/_new  2026-09-29 17:45:35.192696681 +0200
@@ -31,7 +31,8 @@
 Source:         
https://downloads.sourceforge.net/sourceforge/%{name}/%{name}-%{version}.tar.bz2
 Source2:        sysconfig.rpcbind
 Source5:        rpc-user.conf
-Patch:          0001-rpcinfo-fix-stack-buffer-overflow-in-rpcbdump-short-.patch
+Patch1:         0001-rpcinfo-fix-stack-buffer-overflow-in-rpcbdump-short-.patch
+Patch2:         0001-rpcbind-bound-stats-lists-in-rpcbs_getaddr-and-rpcbs.patch
 BuildRequires:  libtirpc-devel >= 1.0.1
 BuildRequires:  libtool
 BuildRequires:  pkgconfig

++++++ 0001-rpcbind-bound-stats-lists-in-rpcbs_getaddr-and-rpcbs.patch ++++++
>From 1aa8081440d6fd86729692d0d5604c3ff583656c Mon Sep 17 00:00:00 2001
From: Scott Mayhew <[email protected]>
Date: Sat, 5 Sep 2026 14:11:49 -0400
Subject: [PATCH] rpcbind: bound stats lists in rpcbs_getaddr() and
 rpcbs_rmtcall()

Limit addrinfo and rmtinfo linked lists to 4096 entries by trimming
the oldest entries from the tail after prepending a new one. This
prevents unbounded memory growth from a large number of unique
program/version/netid combinations.

Assisted-by: Claude:claude-opus-4-6
Signed-off-by: Scott Mayhew <[email protected]>
Signed-off-by: Steve Dickson <[email protected]>
---
 src/rpcb_stat.c | 35 ++++++++++++++++++++++++++++++++---
 1 file changed, 32 insertions(+), 3 deletions(-)

diff --git a/src/rpcb_stat.c b/src/rpcb_stat.c
index 2e5226c..0799a47 100644
--- a/src/rpcb_stat.c
+++ b/src/rpcb_stat.c
@@ -50,6 +50,8 @@
 #include <string.h>
 #include "rpcbind.h"
 
+#define MAX_STAT_BUCKETS 4096
+
 static rpcb_stat_byvers inf;
 
 void
@@ -104,8 +106,9 @@ void
 rpcbs_getaddr(rpcvers_t rtype, rpcprog_t prog, rpcvers_t vers, char *netid,
              char *uaddr)
 {
-       rpcbs_addrlist *al;
+       rpcbs_addrlist *al, *cut = NULL, *tmp;
        struct netconfig *nconf;
+       int listlen = 0;
 
        if (rtype >= RPCBVERS_STAT)
                return;
@@ -121,6 +124,9 @@ rpcbs_getaddr(rpcvers_t rtype, rpcprog_t prog, rpcvers_t 
vers, char *netid,
                                al->success++;
                        return;
                }
+               listlen++;
+               if (listlen == MAX_STAT_BUCKETS - 1)
+                       cut = al;
        }
        nconf = rpcbind_get_conf(netid);
        if (nconf == NULL) {
@@ -142,14 +148,25 @@ rpcbs_getaddr(rpcvers_t rtype, rpcprog_t prog, rpcvers_t 
vers, char *netid,
        }
        al->next = inf[rtype].addrinfo;
        inf[rtype].addrinfo = al;
+
+       if (cut) {
+               al = cut->next;
+               cut->next = NULL;
+               while (al) {
+                       tmp = al;
+                       al = al->next;
+                       free(tmp);
+               }
+       }
 }
 
 void
 rpcbs_rmtcall(rpcvers_t rtype, rpcproc_t rpcbproc, rpcprog_t prog,
              rpcvers_t vers, rpcproc_t proc, char *netid, rpcblist_ptr rbl)
 {
-       rpcbs_rmtcalllist *rl;
+       rpcbs_rmtcalllist *rl, *cut = NULL, *tmp;
        struct netconfig *nconf;
+       int listlen = 0;
 
        if (rtype >= RPCBVERS_STAT)
                return;
@@ -170,6 +187,9 @@ rpcbs_rmtcall(rpcvers_t rtype, rpcproc_t rpcbproc, 
rpcprog_t prog,
                                rl->indirect++;
                        return;
                }
+               listlen++;
+               if (listlen == MAX_STAT_BUCKETS - 1)
+                       cut = rl;
        }
        nconf = rpcbind_get_conf(netid);
        if (nconf == NULL) {
@@ -194,7 +214,16 @@ rpcbs_rmtcall(rpcvers_t rtype, rpcproc_t rpcbproc, 
rpcprog_t prog,
        rl->indirect = 1;
        rl->next = inf[rtype].rmtinfo;
        inf[rtype].rmtinfo = rl;
-       return;
+
+       if (cut) {
+               rl = cut->next;
+               cut->next = NULL;
+               while (rl) {
+                       tmp = rl;
+                       rl = rl->next;
+                       free(tmp);
+               }
+       }
 }
 
 void *
-- 
2.55.0

Reply via email to