{"id":"CVE-2022-23218","description":"The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.","cvssScore":9.8,"cvssVersion":"3.1","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvssMetrics":[{"version":"3.1","score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"},{"version":"3.1","score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","sourceName":"CISA-ADP","type":"Secondary"},{"version":"2.0","score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"cwes":["CWE-120"],"resolved":"OUT-OF-SCOPE","published":"2022-01-14","lastModified":"2026-06-17","affectedProducts":[{"vendor":"gnu","product":"glibc","versionEnd":"\u003c2.31"},{"vendor":"oracle","product":"communications cloud native core unified data repository","version":"22.2.0"},{"vendor":"oracle","product":"enterprise operations monitor","version":"4.3"},{"vendor":"oracle","product":"enterprise operations monitor","version":"4.4"},{"vendor":"oracle","product":"enterprise operations monitor","version":"5.0"},{"vendor":"debian","product":"debian linux","version":"10.0"}],"totalAffectedProducts":4,"references":[{"url":"https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","source":"cve@mitre.org","tags":["Mailing List","Third Party Advisory"]},{"url":"https://security.gentoo.org/glsa/202208-24","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://sourceware.org/bugzilla/show_bug.cgi?id=28768","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","source":"cve@mitre.org","tags":["Patch","Third Party Advisory"]}],"reasoning":{"decidingSource":"h2-out-of-scope-with-cpe","decidingReason":"Manual classification marked OUT-OF-SCOPE but CVE matches known CPE products","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"matched","status":"OUT-OF-SCOPE","detail":"Found in legacy manual classifications","decisive":true}]},"oracleAdvisories":[{"advisory":"Oracle Critical Patch Update October 2022","releaseType":"CPU","quarter":"2022-Q4","url":"https://www.oracle.com/security-alerts/cpuoct2022.html","products":[{"product":"Oracle Communications","component":"Signaling (glibc)","affectedVersions":"22.1.1"}]}],"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"not-needed","type":"none"},"review":{"state":"human","basis":"manual-review"}},"signals":{"hasPOC":false,"pocCount":0},"kev":{"inKEV":false},"epss":{"available":true,"score":0.04729,"percentile":0.91348},"ssvc":{"available":true,"exploitation":"poc","automatable":"yes","technicalImpact":"total"}}