Vulnerability Details CVE-2021-46828
In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled. This can, in turn, lead to an svc_run infinite loop without accepting new connections.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 59.4%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2021-46828
-
cpe:2.3:a:libtirpc_project:libtirpc:0.0.10
-
cpe:2.3:a:libtirpc_project:libtirpc:0.0.9
-
cpe:2.3:a:libtirpc_project:libtirpc:0.1.10
-
cpe:2.3:a:libtirpc_project:libtirpc:0.1.11
-
cpe:2.3:a:libtirpc_project:libtirpc:0.1.8
-
cpe:2.3:a:libtirpc_project:libtirpc:0.1.9
-
cpe:2.3:a:libtirpc_project:libtirpc:0.2.0
-
cpe:2.3:a:libtirpc_project:libtirpc:0.2.1
-
cpe:2.3:a:libtirpc_project:libtirpc:0.2.2
-
cpe:2.3:a:libtirpc_project:libtirpc:0.2.3
-
cpe:2.3:a:libtirpc_project:libtirpc:0.2.4
-
cpe:2.3:a:libtirpc_project:libtirpc:0.2.5
-
cpe:2.3:a:libtirpc_project:libtirpc:0.2.6
-
cpe:2.3:a:libtirpc_project:libtirpc:0.3.0
-
cpe:2.3:a:libtirpc_project:libtirpc:0.3.1
-
cpe:2.3:a:libtirpc_project:libtirpc:0.3.2
-
cpe:2.3:a:libtirpc_project:libtirpc:0.3.3
-
cpe:2.3:a:libtirpc_project:libtirpc:1.0.1
-
cpe:2.3:a:libtirpc_project:libtirpc:1.0.2
-
cpe:2.3:a:libtirpc_project:libtirpc:1.0.3
-
cpe:2.3:a:libtirpc_project:libtirpc:1.0.4
-
cpe:2.3:a:libtirpc_project:libtirpc:1.1.4
-
cpe:2.3:a:libtirpc_project:libtirpc:1.1.5
-
cpe:2.3:o:debian:debian_linux:10.0
-
cpe:2.3:o:debian:debian_linux:11.0