CVE-2018-14622: medium-severity vulnerability in [UNKNOWN] libtirpc
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
A flaw in libtirpc allows a remote attacker to crash RPC-based applications by opening many connections until the server runs out of file descriptors. The application doesn't properly check if a connection setup fails, causing it to crash instead of handling the error gracefully.
A null-pointer dereference occurs in libtirpc's makefd_xprt() function when file descriptor limits are exhausted; the unchecked return value allows remote attackers to trigger application crashes via connection flooding (CWE-252: Unchecked Return Value). The vulnerability requires the ability to send network traffic to an RPC service and affects availability through denial of service.
In the same product, most dangerous first.