Uclibc Ng Project maintains a lightweight C standard library implementation widely used in embedded systems and resource-constrained environments where full glibc overhead is impractical. The project's narrow product scope belies its broad embedded footprint across routers, IoT devices, and custom appliances where it serves as a critical system component. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uclibc Ng Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29503CRITICAL A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread allocation can lead to memory corruption. An a | Sep 29, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-27419CRITICAL uClibc-ng versions prior to 1.0.37 are vulnerable to integer wrap-around in functions malloc-simple. This improper memory assignment can lead to arbitrary memory allocation, result | May 3, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-43523CRITICAL In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnamein | Nov 10, 2021 | 9.6 | 30 | NO | NO |
CVE-2022-30295MEDIUM uClibc-ng through 1.0.40 and uClibc through 0.9.33.2 use predictable DNS transaction IDs that may lead to DNS cache poisoning. This is related to a reset of a value to 0x2. | May 6, 2022 | 6.5 | 28 | NO | NO |
CVE-2016-2225HIGH The __read_etc_hosts_r function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) via a crafted packet. | Mar 24, 2017 | 7.5 | 25 | NO | NO |
CVE-2016-2224HIGH The __decode_dotted function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) via vectors involving compresse | Mar 24, 2017 | 7.5 | 25 | NO | NO |
CVE-2016-6264HIGH Integer signedness error in libc/string/arm/memset.S in uClibc and uClibc-ng before 1.0.16 allows context-dependent attackers to cause a denial of service (crash) via a negative le | Jan 27, 2017 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uclibc Ng Project.
Media articles that mention a CVE ID that affects a product developed by Uclibc Ng Project — matched by CVE ID, not by vendor name.