« Volver al listado

CVE-2022-29503

Estado: ModificadaCrítica (9.8)—

A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread allocation can lead to memory corruption. An attacker can create threads to trigger this vulnerability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-29503",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-29503",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-15T18:18:03.608210Z"
        }
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "talos-cna@cisco.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.2
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "talos-cna@cisco.com",
      "affectedData": [
        {
          "vendor": "Anker",
          "product": "Eufy Homebase 2",
          "versions": [
            {
              "status": "affected",
              "version": "2.1.8.8h"
            }
          ]
        },
        {
          "vendor": "Anker",
          "product": "Eufy Homebase 2",
          "versions": [
            {
              "status": "affected",
              "version": "2.1.8.8h"
            }
          ]
        },
        {
          "vendor": "Anker",
          "product": "Eufy Homebase 2",
          "versions": [
            {
              "status": "affected",
              "version": "2.1.8.8h"
            }
          ]
        },
        {
          "vendor": "Anker",
          "product": "Eufy Homebase 2",
          "versions": [
            {
              "status": "affected",
              "version": "2.1.8.8h"
            }
          ]
        },
        {
          "vendor": "uClibC",
          "product": "uClibC",
          "versions": [
            {
              "status": "affected",
              "version": "0.9.33.2"
            }
          ]
        },
        {
          "vendor": "uClibC",
          "product": "uClibC",
          "versions": [
            {
              "status": "affected",
              "version": "0.9.33.2"
            }
          ]
        },
        {
          "vendor": "uClibC",
          "product": "uClibC",
          "versions": [
            {
              "status": "affected",
              "version": "0.9.33.2"
            }
          ]
        },
        {
          "vendor": "uClibC",
          "product": "uClibC",
          "versions": [
            {
              "status": "affected",
              "version": "0.9.33.2"
            }
          ]
        },
        {
          "vendor": "uClibC-ng",
          "product": "uClibC-ng",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.40"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-09-29T17:15:28.723",
  "references": [
    {
      "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2022-1517",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "talos-cna@cisco.com"
    },
    {
      "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2022-1517",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "talos-cna@cisco.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-770"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread allocation can lead to memory corruption. An attacker can create threads to trigger this vulnerability."
    },
    {
      "lang": "es",
      "value": "Se presenta vulnerabilidad de corrupción de memoria en la funcionalidad libpthread linuxthreads de uClibC versión 0.9.33.2 y uClibC-ng versión 1.0.40. Una asignación de hilos puede conllevar a una corrupción de memoria. Un atacante puede crear hilos para desencadenar esta vulnerabilidad"
    }
  ],
  "lastModified": "2026-06-17T04:40:19.690",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:uclibc:uclibc:0.9.33.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BDD7DBF9-06F5-44EC-BA62-61AF6D1FCC72"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:uclibc-ng_project:uclibc-ng:1.0.40:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E0D2B754-D26E-43F0-98FF-50746C422DCA"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:anker:eufy_homebase_2_firmware:2.1.8.8h:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0897DDF8-D5AA-422F-8916-E790D35DBE58"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:anker:eufy_homebase_2:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "52EB1932-8EEB-4644-BDE4-1585650729E7"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "talos-cna@cisco.com"
}