CVE-2016-6264: Uclibc
High severity, CVSS 7.5. EPSS: 2.7% chance of exploitation in the next 30 days.
Integer signedness error in libc/string/arm/memset.S in uClibc and uClibc-ng before 1.0.16 allows context-dependent attackers to cause a denial of service (crash) via a negative length value to the memset function.
Affected products
- Uclibc Uclibc: affected versions not specified
- Uclibc-NG Project Uclibc-NG: before 1.0.16 (fixed in 1.0.16)
Published 2017-01-27. Last modified 2026-06-17.