Vulnerability Description
The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Glibc | < 2.31 |
| Oracle | Communications Cloud Native Core Unified Data Repository | 22.2.0 |
| Oracle | Enterprise Operations Monitor | 4.3 |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- https://lists.debian.org/debian-lts-announce/2022/10/msg00021.htmlMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202208-24Third Party Advisory
- https://sourceware.org/bugzilla/show_bug.cgi?id=28768ExploitIssue TrackingThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/10/msg00021.htmlMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202208-24Third Party Advisory
- https://sourceware.org/bugzilla/show_bug.cgi?id=28768ExploitIssue TrackingThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatchThird Party Advisory
FAQ
What is CVE-2022-23218?
CVE-2022-23218 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may r...
How severe is CVE-2022-23218?
CVE-2022-23218 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-23218?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Glibc, Oracle Communications Cloud Native Core Unified Data Repository, Oracle Enterprise Operations Monitor, Debian Debian Linux.