{"id":"CVE-2016-6264","details":"Integer signedness error in libc/string/arm/memset.S in uClibc and uClibc-ng before 1.0.16 allows context-dependent attackers to cause a denial of service (crash) via a negative length value to the memset function.","modified":"2026-07-08T12:52:56.787335Z","published":"2017-01-27T22:59:00.740Z","references":[{"type":"ADVISORY","url":"http://mailman.uclibc-ng.org/pipermail/devel/2016-July/001067.html"},{"type":"ADVISORY","url":"http://mailman.uclibc-ng.org/pipermail/devel/2016-May/000890.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/91492"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2016/06/29/3"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2016/07/21/2"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2016/07/21/6"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wbx-github/uclibc-ng","events":[{"introduced":"0"},{"fixed":"aebdbb727362a92437b772e5d749d6650e5b823f"}],"database_specific":{"cpe":"cpe:2.3:a:uclibc-ng_project:uclibc-ng:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.0.16"}],"source":"CPE_RANGE"}}],"versions":["v1.0.15","v1.0.14","v1.0.13","v1.0.12","v1.0.11","v1.0.10","v1.0.9","v1.0.8","v1.0.7","v1.0.6","v1.0.5","v1.0.4","v1.0.2","v1.0.1","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-6264.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}