MGASA-2022-0028

Advisory lineage Upstream: 2 Downstream: 0
Published: 23 Jan 2022, 20:50
Last modified:16 Apr 2026, 04:41

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 Jan 2022, 20:50
Published
Vulnerability first disclosed
16 Apr 2026, 04:41
Last Modified
Vulnerability information updated

Description

Updated glibc packages fix security vulnerabilities Updated glibc packages fix security vulnerabilities: The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution (CVE-2022-23218). The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution (CVE-2022-23219).

Affected Systems

  • mageiaglibc

    < 2.32-23.mga8

References (2)