Klibc is a minimal C library designed for early-stage kernel initialization and embedded boot environments, where its compact footprint and specialized role make it distinct from general-purpose libc implementations. The observed vulnerability surface reflects the numeric-handling demands of low-level boot code, with exposure centered on integer overflow conditions and related boundary-case handling in the klibc product itself. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Klibc Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-1930CRITICAL In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHC | Nov 14, 2019 | 9.8 | 51 | NO | YES |
CVE-2021-31872CRITICAL An issue was discovered in klibc before 2.0.9. Multiple possible integer overflows in the cpio command on 32-bit systems may result in a buffer overflow or other security impact. | Apr 30, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-31873CRITICAL An issue was discovered in klibc before 2.0.9. Additions in the malloc() function may result in an integer overflow and a subsequent heap buffer overflow. | Apr 30, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-31870CRITICAL An issue was discovered in klibc before 2.0.9. Multiplication in the calloc() function may result in an integer overflow and a subsequent heap buffer overflow. | Apr 30, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-31871HIGH An issue was discovered in klibc before 2.0.9. An integer overflow in the cpio command may result in a NULL pointer dereference on 64-bit systems. | Apr 30, 2021 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Klibc Project.
Media articles that mention a CVE ID that affects a product developed by Klibc Project — matched by CVE ID, not by vendor name.