CVE-2022-23218: Buffer Overflow
Last updated 24 July 2024
Other sources
The deprecated compatibility function svcunixcreate in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-23218?
CVE-2022-23218 is a vulnerability in the GNU C Library (glibc) that allows for a buffer overflow, potentially leading to a denial of service or arbitrary code execution.
How severe is CVE-2022-23218?
CVE-2022-23218 has a severity rating of 9.8, which is considered critical.
Which software is affected by CVE-2022-23218?
GNU glibc up to version 2.34, Oracle Communications Cloud Native Core Unified Data Repository version 22.2.0, Oracle Enterprise Operations Monitor versions 4.3, 4.4, and 5.0, and Debian Debian Linux version 10.0 are affected by CVE-2022-23218.
How can I fix CVE-2022-23218?
To fix CVE-2022-23218, it is recommended to update to the latest version of the affected software.
Where can I find more information about CVE-2022-23218?
More information about CVE-2022-23218 can be found at the following references: [link1], [link2], [link3].