PT-2021-7628 · Ncurses+9 · Ncurses+9

Éæ

·

Published

2021-10-21

·

Updated

2025-08-06

·

CVE-2022-29458

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions ncurses versions 6.3 through 6.3 before patch 20220416
Description The issue is related to an out-of-bounds read and segmentation violation in the convert strings function in tinfo/read entry.c within the terminfo library. This can allow an attacker to access confidential data and cause a denial-of-service. The vulnerability is associated with reading beyond the valid boundaries of a data buffer.
Recommendations For ncurses version 6.3 before patch 20220416, apply the patch 20220416 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3249
ALT-PU-2023-1890
ALT-PU-2024-8032
AZL-9497
BDU:2023-00296
CVE-2022-29458
DLA-3167-1
INFSA-2025_12876
OESA-2022-1635
OPENSUSE-SU-2022_2717-1
OPENSUSE-SU-2024:12020-1
RHSA-2025:12876
RHSA-2025:16414
RHSA-2025:16418
RHSA-2025:17006
RHSA-2025_12876
ROSA-SA-2023-2263
SUSE-SU-2022:2717-1
SUSE-SU-2022:2717-2
SUSE-SU-2022:2718-1
SUSE-SU-2022_2717-1
SUSE-SU-2022_2718-1
USN-5477-1
USN-6099-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Apple Macos
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Ncurses