Newlib is a lightweight standard C library widely embedded in embedded systems, real-time operating systems, and firmware across IoT devices, microcontrollers, and other resource-constrained platforms, where its narrow product scope masks deep supply-chain reach. Vulnerabilities affecting the vendor skew toward serious outcomes, clustering around memory-safety and arithmetic issues such as NULL pointer dereferences, integer overflows, and out-of-bounds writes that are characteristic of C standard library implementations. Defenders should track this vendor's releases because a single flaw can propagate across countless downstream embedded products and firmware images; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Newlib Project over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3420CRITICAL A flaw was found in newlib in versions prior to 4.0.0. Improper overflow validation in the memory allocation functions mEMALIGn, pvALLOc, nano_memalign, nano_valloc, nano_pvalloc c | Mar 5, 2021 | 9.8 | 31 | NO | NO |
CVE-2024-30949CRITICAL An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the time unit scaling in the _gettimeofday function. | Aug 20, 2024 | 9.8 | 25 | NO | NO |
CVE-2019-14878MEDIUM In the __d2b function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocate a big integer, however no check is perfor | Mar 19, 2020 | 6.5 | 22 | NO | NO |
CVE-2019-14875MEDIUM In the __multiply function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocate a big integer, however no check is p | Mar 19, 2020 | 6.5 | 22 | NO | NO |
CVE-2019-14874MEDIUM In the __i2b function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocate a big integer, however no check is perfor | Mar 19, 2020 | 6.5 | 22 | NO | NO |
CVE-2019-14872MEDIUM The _dtoa_r function of the newlib libc library, prior to version 3.3.0, performs multiple memory allocations without checking their return value. This could result in NULL pointer | Mar 19, 2020 | 6.5 | 22 | NO | NO |
CVE-2019-14877MEDIUM In the __mdiff function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocate big integers, however no check is perfo | Mar 19, 2020 | 6.5 | 21 | NO | NO |
CVE-2019-14876MEDIUM In the __lshift function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocate a big integer, however no check is per | Mar 19, 2020 | 6.5 | 21 | NO | NO |
CVE-2019-14873MEDIUM In the __multadd function of the newlib libc library, prior to versions 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocate a big integer, however no check is perfor | Mar 19, 2020 | 6.5 | 21 | NO | NO |
CVE-2019-14871MEDIUM The REENT_CHECK macro (see newlib/libc/include/sys/reent.h) as used by REENT_CHECK_TM, REENT_CHECK_MISC, REENT_CHECK_MP and other newlib macros in versions prior to 3.3.0, does not | Mar 18, 2020 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Newlib Project.
Media articles that mention a CVE ID that affects a product developed by Newlib Project — matched by CVE ID, not by vendor name.