CVE-2018-14621

An infinite loop vulnerability was found in libtirpc before version 1.0.2-rc2. With the port to using poll rather than select, exhaustion of file descriptors would cause the server to enter an infinite loop, consuming a large amount of CPU time and denying service to other clients until restarted.
Infinite Loop
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
redhatCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
VendorProductVersion
libtirpc_projectlibtirpc
𝑥
≤ 1.0.1
libtirpc_projectlibtirpc
1.0.2:rc1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libtirpc
bullseye (security)
1.3.1-1+deb11u1
fixed
bullseye
1.3.1-1+deb11u1
fixed
bookworm
1.3.3+ds-1
fixed
sid
1.3.4+ds-1.3
fixed
trixie
1.3.4+ds-1.3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libtirpc
bionic
not-affected
xenial
not-affected
trusty
not-affected