CVE-2020-28928: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.7% chance of exploitation in the next 30 days.

In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid write access (buffer overflow).

Affected products

  • Debian Debian Linux: version 9.0 only
  • Fedoraproject Fedora: version 33 only; version 34 only
  • Musl-Libc Musl: up to and including 1.2.1
  • Oracle Graalvm: version 20.3.2 only; version 21.1.0 only

Published 2020-11-24. Last modified 2026-06-17.