Uclibc is a lightweight C standard library implementation widely embedded in embedded systems, IoT devices, and resource-constrained environments where it serves as a core runtime dependency. Vulnerabilities affecting the library skew strongly toward critical-severity outcomes and center on memory-safety and input-handling weaknesses—including resource exhaustion, cross-site scripting, buffer boundary violations, and out-of-bounds reads—that reflect the parsing and memory-management demands of a foundational C library. Defenders should prioritize inventory of downstream products and firmware that embed this library, since remediation depends on those products rebuilding and issuing updates; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uclibc over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29503CRITICAL A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread allocation can lead to memory corruption. An a | Sep 29, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-43523CRITICAL In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnamein | Nov 10, 2021 | 9.6 | 30 | NO | NO |
CVE-2017-9728CRITICAL In uClibc 0.9.33.2, there is an out-of-bounds read in the get_subexp function in misc/regex/regexec.c when processing a crafted regular expression. | Jun 16, 2017 | 9.8 | 29 | NO | NO |
CVE-2022-30295MEDIUM uClibc-ng through 1.0.40 and uClibc through 0.9.33.2 use predictable DNS transaction IDs that may lead to DNS cache poisoning. This is related to a reset of a value to 0x2. | May 6, 2022 | 6.5 | 28 | NO | NO |
CVE-2017-9729HIGH In uClibc 0.9.33.2, there is stack exhaustion (uncontrolled recursion) in the check_dst_limits_calc_pos_1 function in misc/regex/regexec.c when processing a crafted regular express | Jun 16, 2017 | 7.5 | 24 | NO | NO |
CVE-2016-6264HIGH Integer signedness error in libc/string/arm/memset.S in uClibc and uClibc-ng before 1.0.16 allows context-dependent attackers to cause a denial of service (crash) via a negative le | Jan 27, 2017 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uclibc.
Media articles that mention a CVE ID that affects a product developed by Uclibc — matched by CVE ID, not by vendor name.