{"id":"CVE-2022-23219","description":"The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.","cvssScore":9.8,"cvssVersion":"3.1","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvssMetrics":[{"version":"3.1","score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"},{"version":"3.1","score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","sourceName":"CISA-ADP","type":"Secondary"},{"version":"2.0","score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"cwes":["CWE-120"],"resolved":"OUT-OF-SCOPE","published":"2022-01-14","lastModified":"2026-06-17","affectedProducts":[{"vendor":"gnu","product":"glibc","versionEnd":"\u003c2.31"},{"vendor":"oracle","product":"communications cloud native core binding support function","version":"22.1.3"},{"vendor":"oracle","product":"communications cloud native core network function cloud native environment","version":"22.1.0"},{"vendor":"oracle","product":"communications cloud native core network repository function","version":"22.1.2"},{"vendor":"oracle","product":"communications cloud native core network repository function","version":"22.2.0"},{"vendor":"oracle","product":"communications cloud native core security edge protection proxy","version":"22.1.1"},{"vendor":"oracle","product":"communications cloud native core unified data repository","version":"22.2.0"},{"vendor":"oracle","product":"enterprise operations monitor","version":"4.3"},{"vendor":"oracle","product":"enterprise operations monitor","version":"4.4"},{"vendor":"oracle","product":"enterprise operations monitor","version":"5.0"},{"vendor":"debian","product":"debian linux","version":"10.0"}],"totalAffectedProducts":8,"references":[{"url":"https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html","source":"cve@mitre.org","tags":["Mailing List","Third Party Advisory"]},{"url":"https://security.gentoo.org/glsa/202208-24","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://sourceware.org/bugzilla/show_bug.cgi?id=22542","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","source":"cve@mitre.org","tags":["Patch","Third Party Advisory"]}],"reasoning":{"decidingSource":"h2-out-of-scope-with-cpe","decidingReason":"Manual classification marked OUT-OF-SCOPE but CVE matches known CPE products","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"matched","status":"OUT-OF-SCOPE","detail":"Found in legacy manual classifications","decisive":true}]},"oracleAdvisories":[{"advisory":"Oracle Critical Patch Update January 2023","releaseType":"CPU","quarter":"2023-Q1","url":"https://www.oracle.com/security-alerts/cpujan2023.html","products":[{"product":"Oracle Systems","component":"XCP Firmware (glibc)","affectedVersions":"Prior to XCP2411, prior to XCP3111, prior to XCP4011"}]},{"advisory":"Oracle Critical Patch Update October 2022","releaseType":"CPU","quarter":"2022-Q4","url":"https://www.oracle.com/security-alerts/cpuoct2022.html","products":[{"product":"Oracle Communications","component":"Routing (glibc)","affectedVersions":"8.4, 9.0, 9.1"}]},{"advisory":"Oracle Critical Patch Update July 2022","releaseType":"CPU","quarter":"2022-Q3","url":"https://www.oracle.com/security-alerts/cpujul2022.html","products":[{"product":"Oracle Communications","component":"BSF (glibc)","affectedVersions":"22.1.3"},{"product":"Oracle Communications","component":"CNE (glibc)","affectedVersions":"22.1.0"},{"product":"Oracle Communications","component":"Mediation Engine (glibc)","affectedVersions":"4.3, 4.4, 5.0"},{"product":"Oracle Communications","component":"NRF (glibc)","affectedVersions":"22.1.2, 22.2.0"},{"product":"Oracle Communications","component":"SEPP (glibc)","affectedVersions":"22.1.1"},{"product":"Oracle Communications","component":"UDR (glibc)","affectedVersions":"22.2.0"}]}],"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"not-needed","type":"none"},"review":{"state":"human","basis":"manual-review"}},"signals":{"hasPOC":false,"pocCount":0},"kev":{"inKEV":false},"epss":{"available":true,"score":0.04211,"percentile":0.90433},"ssvc":{"available":true,"exploitation":"poc","automatable":"yes","technicalImpact":"total"}}