CVE-2019-14872: Newlib Project Newlib
Medium severity, CVSS 6.5. EPSS: 1.5% chance of exploitation in the next 30 days.
The _dtoa_r function of the newlib libc library, prior to version 3.3.0, performs multiple memory allocations without checking their return value. This could result in NULL pointer dereference.
Affected products
- Newlib Project Newlib: before 3.3.0 (fixed in 3.3.0)
Published 2020-03-19. Last modified 2026-06-17.