CVE-2016-6264: Uclibc

High severity, CVSS 7.5. EPSS: 2.7% chance of exploitation in the next 30 days.

Integer signedness error in libc/string/arm/memset.S in uClibc and uClibc-ng before 1.0.16 allows context-dependent attackers to cause a denial of service (crash) via a negative length value to the memset function.

Affected products

Published 2017-01-27. Last modified 2026-06-17.