CVE-2020-29361: Debian Linux
High severity, CVSS 7.5. EPSS: 3.4% chance of exploitation in the next 30 days.
An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or calloc.
Affected products
- Debian Debian Linux: version 9.0 only; version 10.0 only
- p11-Kit Project p11-Kit: from 0.21.1, up to and including 0.23.21
Published 2020-12-16. Last modified 2026-06-17.