CVE-2023-29491: Invisible-Island Ncurses

High severity, CVSS 7.8. EPSS: 0.9% chance of exploitation in the next 30 days.

ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.

Affected products

Published 2023-04-14. Last modified 2026-07-27.