CVE-2022-4904: C-Ares Project C-Ares
High severity, CVSS 8.6. EPSS: 1.2% chance of exploitation in the next 30 days.
A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.
Affected products
- C-Ares Project C-Ares: before 1.19.0 (fixed in 1.19.0)
- Fedoraproject Fedora: version 36 only
- Red Hat Enterprise Linux: version 8.0 only; version 9.0 only
- Red Hat Software Collections: affected versions not specified
Published 2023-03-06. Last modified 2026-06-17.