<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://test-devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>uCLibC Zero Day</title><link>https://test-devzone.nordicsemi.com/f/nordic-q-a/87817/uclibc-zero-day</link><description>Hello! 
 Following the uClibC zero day exploit that was disclosed recently: https://portswigger.net/daily-swig/zero-day-bug-in-uclibc-library-could-leave-iot-devices-vulnerable-to-dns-poisoning-attacks 
 Is there any lib (like the modem lib,..) that could</description><dc:language>en-US</dc:language><generator>Telligent Community 13 Non-Production</generator><lastBuildDate>Fri, 13 May 2022 10:07:39 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://test-devzone.nordicsemi.com/f/nordic-q-a/87817/uclibc-zero-day" /><item><title>RE: uCLibC Zero Day</title><link>https://test-devzone.nordicsemi.com/thread/367791?ContentTypeID=1</link><pubDate>Fri, 13 May 2022 10:07:39 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:819c8149-9048-4291-9d92-05885b4c9d1f</guid><dc:creator>user2115</dc:creator><description>&lt;p&gt;Hi again,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;uClibC is not used in Modem FW, so we are not vulnerable to this exploit.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Kind regards,&lt;/p&gt;
&lt;p&gt;Håkon&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: uCLibC Zero Day</title><link>https://test-devzone.nordicsemi.com/thread/367599?ContentTypeID=1</link><pubDate>Thu, 12 May 2022 12:12:52 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:1d8f6b8e-a1d1-4ab5-a28d-c333163a681f</guid><dc:creator>user2115</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;nrf_modem (libmodem) inherits from the application, which is normally newlib-nano or zephyr minimal libc.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Currently verifying internally on the modem itself.&amp;nbsp;&lt;span style="font-family:inherit;"&gt;I&amp;#39;ll get back to you within 2 working days.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Kind regards,&lt;/p&gt;
&lt;p&gt;Håkon&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>