CVE-2022-4904: C-Ares Project C-Ares

High severity, CVSS 8.6. EPSS: 1.2% chance of exploitation in the next 30 days.

A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.

Affected products

  • C-Ares Project C-Ares: before 1.19.0 (fixed in 1.19.0)
  • Fedoraproject Fedora: version 36 only
  • Red Hat Enterprise Linux: version 8.0 only; version 9.0 only
  • Red Hat Software Collections: affected versions not specified

Published 2023-03-06. Last modified 2026-06-17.