CVE-2020-12762: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 1.9% chance of exploitation in the next 30 days.

json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only; version 19.10 only; version 20.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • Fedoraproject Fedora: version 30 only; version 31 only; version 32 only
  • JSON-C JSON-C: before 0.15-20200726 (fixed in 0.15-20200726)
  • Siemens Sinec Ins: affected versions not specified; version 1.0 only

Published 2020-05-09. Last modified 2026-06-17.