← Vulnerability feed

Vulnerability record · CVE-2022-29503 · published 29 September 2022

CVE-2022-29503: Uclibc memory buffer overflow vulnerability

Uclibc · Uclibc

A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread allocation can lead to memory corruption. An attacker can create threads to trigger this vulnerability.

9.8 CVSS 3.1 Critical EPSS 1.3% · top 30.6% CWE-119 · Memory buffer overflowCWE-770 · Allocation without limits
9.8CVSS 3.1 base score
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread allocation can lead to memory corruption. An attacker can create threads to trigger this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-29503 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-21950Anker eufy homebase 2 firmware memory buffer overflow vulnerabilityAn out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Eufy Homebas…EPSS 2.4%10.0CVE-2021-21951Anker eufy homebase 2 firmware memory buffer overflow vulnerabilityAn out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Eufy Homebas…EPSS 2.4%10.0CVE-2021-21940Anker eufy homebase 2 firmware heap-based buffer overflow vulnerabilityA heap-based buffer overflow vulnerability exists in the pushMuxer processRtspInfo functionality of Anker Eufy Homebase 2 2.1.6.9h. A specially-craft…EPSS 1.3%9.9CVE-2021-21954Anker eufy homebase 2 firmware os command injection vulnerabilityA command execution vulnerability exists in the wifi_country_code_update functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h.…EPSS 2.4%9.8CVE-2022-21806Anker eufy homebase 2 firmware use after free vulnerabilityA use-after-free vulnerability exists in the mips_collector appsrv_server functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted set of…EPSS 2.3%9.8CVE-2021-27419Uclibc-ng project uclibc-ng integer overflow vulnerabilityuClibc-ng versions prior to 1.0.37 are vulnerable to integer wrap-around in functions malloc-simple. This improper memory assignment can lead to arbi…EPSS 1.7%9.8CVE-2021-21952Anker eufy homebase 2 firmware authentication bypass via alternate path vulnerabilityAn authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality of the home_security binary of Anker Eufy Homebase …EPSS 1.3%9.8CVE-2017-9728Uclibc out-of-bounds read vulnerabilityIn uClibc 0.9.33.2, there is an out-of-bounds read in the get_subexp function in misc/regex/regexec.c when processing a crafted regular expression.EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2022-29503), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.