CVE-2020-29361: Debian Linux

High severity, CVSS 7.5. EPSS: 3.4% chance of exploitation in the next 30 days.

An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or calloc.

Affected products

  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • p11-Kit Project p11-Kit: from 0.21.1, up to and including 0.23.21

Published 2020-12-16. Last modified 2026-06-17.