CVE-2022-23219: Debian Linux

Critical severity, CVSS 9.8. EPSS: 4.3% chance of exploitation in the next 30 days.

The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.

Affected products

  • Debian Debian Linux: version 10.0 only
  • GNU Glibc: before 2.31 (fixed in 2.31)
  • Oracle Communications Cloud Native Core Binding Support Function: version 22.1.3 only
  • Oracle Communications Cloud Native Core Network Function Cloud Native Environment: version 22.1.0 only
  • Oracle Communications Cloud Native Core Network Repository Function: version 22.1.2 only; version 22.2.0 only
  • Oracle Communications Cloud Native Core Security Edge Protection Proxy: version 22.1.1 only
  • Oracle Communications Cloud Native Core Unified Data Repository: version 22.2.0 only
  • Oracle Enterprise Operations Monitor: version 4.3 only; version 4.4 only; version 5.0 only

Published 2022-01-14. Last modified 2026-06-17.