cbcvebase.
CVE-2022-23218
published 2022-01-14

CVE-2022-23218: The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.

Affected

16 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianglibc< glibc 2.33-3 (bookworm)glibc 2.33-3 (bookworm)
gnuglibc< 2.312.31
gnuglibc>= 0 < 2.31-13+deb11u32.31-13+deb11u3
gnuglibc>= 0 < 2.33-32.33-3
gnuglibc>= 0 < 2.33-32.33-3
gnuglibc>= 0 < 2.33-32.33-3
gnuglibc>= 0 < 2.27-3ubuntu1.52.27-3ubuntu1.5
gnuglibc>= 0 < 2.31-0ubuntu9.72.31-0ubuntu9.7
gnuglibc>= 0 < 2.23-0ubuntu11.3+esm12.23-0ubuntu11.3+esm1
msrccbl2_glibc_2.35-1_on_cbl_mariner_2.0
oraclecommunications_cloud_native_core_unified_data_repository
oracleenterprise_operations_monitor
oracleenterprise_operations_monitor
oracleenterprise_operations_monitor
paloaltopan-os

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL