First published: Thu Sep 29 2022(Updated: )
A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread allocation can lead to memory corruption. An attacker can create threads to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Uclibc Uclibc | =0.9.33.2 | |
Uclibc-ng Project Uclibc-ng | =1.0.40 | |
Anker Eufy Homebase 2 Firmware | =2.1.8.8h | |
Anker Eufy Homebase 2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29503 has a severity rating that indicates a significant risk of memory corruption due to thread allocation.
To fix CVE-2022-29503, update to the latest versions of uClibC or uClibC-ng that address this vulnerability.
CVE-2022-29503 affects uClibC version 0.9.33.2 and uClibC-ng version 1.0.40.
Exploitation of CVE-2022-29503 can lead to memory corruption, potentially allowing an attacker to disrupt services or execute arbitrary code.
Yes, CVE-2022-29503 is also noted to affect Anker Eufy Homebase 2 firmware version 2.1.8.8h.