CVE-2022-29503 is a critical memory corruption vulnerability affecting the libpthread linuxthreads functionality in uClibC versions 0.9.33.2 and uClibC-ng 1.0.40, including products like Anker. This flaw, rated 9.8 CVSS (Critical), allows an unauthenticated attacker to remotely trigger memory corruption by creating threads, leading to high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, its high FAUCET Risk Score of 79/100 indicates significant potential risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.9.33.2CPE matchmatch criteria | cpe:2.3:a:uclibc:uclibc:0.9.33.2:*:*:*:*:*:*:* | ||
1.0.40CPE matchmatch criteria | cpe:2.3:a:uclibc-ng_project:uclibc-ng:1.0.40:*:*:*:*:*:*:* | ||
2.1.8.8hCPE matchmatch criteria | cpe:2.3:o:anker:eufy_homebase_2_firmware:2.1.8.8h:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2022-29503
Jul 11, 2023A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread allocation can lead to memory corruption. An attacker can create threads to trigger this vulnerability.
Sep 13, 2022