Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-29458

27
FAUCET Score

CVE-2022-29458 is an out-of-bounds read vulnerability in ncurses 6.3 prior to patch 20220416, specifically within the convert_strings function of the terminfo library. This flaw can lead to a segmentation violation and affects various distributions of Apple macOS and Debian Linux, as well as the ncurses library itself. Rated with a CVSS score of 7.1 (High), this vulnerability requires user interaction (UI:R) and local access (AV:L) to exploit, but has low attack complexity (AC:L). A successful exploit could result in high confidentiality impact (C:H) and high availability impact (A:H), potentially leading to information disclosure or system crashes. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has garnered minimal community discussion and media coverage, suggesting a low level of public awareness or concern.

Impacted Technologies

VendorProductVersion(s)CPE
< 6.3CPE matchmatch criteria
cpe:2.3:a:gnu:ncurses:*:*:*:*:*:*:*:*
6.3CPE matchmatch criteria
cpe:2.3:a:invisible-island:ncurses:6.3:-:*:*:*:*:*:*
< 13.0CPE matchmatch criteria
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.34%
Probability of exploitation in next 30 days
EPSS Percentile
68.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0134 is in the 66th percentile among its peer group of 11,616 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

microsoftpatch availablevia msrc
Product: 18739-16820Fixed in: 6.3-2
microsoftpatch availablevia msrc
Product: 18740-16823Fixed in: 6.3-2
microsoftpatch availablevia msrc
Product: cm1 ncurses 6.3-2 on CBL Mariner 1.0Fixed in: 6.3-2
microsoftpatch availablevia msrc
Product: cbl2 ncurses 6.3-2 on CBL Mariner 2.0Fixed in: 6.3-2
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: ncurses-0:6.2-8.20210508.el9_2.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: ncurses-0:6.2-10.20210508.el9_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 7Fixed in: rhceph/rhceph-7-rhel9:sha256:ce213d48fbefae6b9d5f5a64b79c6ed016afcb646bf7b5742707ed31f9a464a2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: ncurses-0:6.2-10.20210508.el9_6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: ncurses-0:6.2-8.20210508.el9_0.1
View patch

Vendor Advisories (2)

redhatCVE-2022-29458Low

ncurses: segfaulting OOB read

Apr 18, 2022
microsoft2022-Apr/CVE-2022-29458Important

ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.

Apr 12, 2022

References

seclists.org / fulldisclosure/2022/Oct/28
seclists.org / fulldisclosure/2022/Oct/41
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2022/10/msg00037.html
Mailing ListThird Party Advisory
lists.gnu.org / archive/html/bug-ncurses/2022-04/msg00014.html
ExploitMailing ListVendor Advisory
lists.gnu.org / archive/html/bug-ncurses/2022-04/msg00016.html
Mailing ListVendor Advisory
support.apple.com / kb/HT213488
Third Party Advisory