Vulnerability record · CVE-2002-0391 · published 12 August 2002
CVE-2002-0391: SunRPC xdr_array integer overflow enables remote code execution
Freebsd · Freebsd
The xdr_array function in SunRPC-derived RPC libraries (libc, glibc, dietlibc and others) contains an integer overflow when processing the argument count. A remote attacker can pass a large number of arguments through RPC services such as rpc.cmsd and dmispd, corrupting memory. Because the flaw sits in widely shared RPC code, it affects many operating systems and services at once.
Description
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, remote code execution in shared RPC code, and very high EPSS despite absence from KEV.
What it is
The xdr_array function in SunRPC-derived RPC libraries (libc, glibc, dietlibc and others) contains an integer overflow when processing the argument count. A remote attacker can pass a large number of arguments through RPC services such as rpc.cmsd and dmispd, corrupting memory. Because the flaw sits in widely shared RPC code, it affects many operating systems and services at once.
Impact
Successful exploitation allows a remote attacker to execute arbitrary code, typically with the privileges of the RPC service, which on many systems is root. This gives full control of the affected host.
Attack surface
Reachable over the network through RPC services that call xdr_array, including rpc.cmsd and dmispd. The CVSS vector shows no privileges and no user interaction required, so any host exposing a vulnerable RPC service is directly reachable.
Exploitation
Not listed in CISA KEV, but EPSS is 0.58133 (99th percentile), indicating high predicted exploitation activity. Multiple references are tagged Exploit, confirming public exploit material exists.
What to do
- Apply vendor patches for the RPC libraries and affected services (Sun, Microsoft, FreeBSD, OpenBSD and Linux distributions) as the first action.
- Disable or block RPC services that are not required, particularly rpc.cmsd and dmispd.
- Restrict RPC ports with host and network firewalls so only trusted hosts can reach them.
- Where patching is not possible, isolate affected systems from untrusted networks.
- Monitor vendor advisories for updated fixes since many original reference links are broken.
Detection
- Monitor RPC traffic for unusually large argument counts or malformed XDR payloads targeting rpc.cmsd, dmispd and similar services.
- Watch for unexpected process crashes or restarts of RPC daemons, which can indicate exploitation attempts.
- Alert on new or unusual outbound connections or child processes spawned by RPC service accounts.
- Audit exposed RPC ports and flag any internet-facing RPC services in the environment.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2002-0391 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2002-0391), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.