CVE-2022-23218: Debian Linux
Critical severity, CVSS 9.8. EPSS: 4.8% chance of exploitation in the next 30 days.
The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
Affected products
- Debian Debian Linux: version 10.0 only
- GNU Glibc: before 2.31 (fixed in 2.31)
- Oracle Communications Cloud Native Core Unified Data Repository: version 22.2.0 only
- Oracle Enterprise Operations Monitor: version 4.3 only; version 4.4 only; version 5.0 only
Published 2022-01-14. Last modified 2026-06-17.