CVE-2020-29363: Debian Linux

High severity, CVSS 7.5. EPSS: 3.5% chance of exploitation in the next 30 days.

An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the client library. When the remote entity supplies a serialized byte array in a CK_ATTRIBUTE, the receiving entity may not allocate sufficient length for the buffer to store the deserialized value.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Oracle Communications Cloud Native Core Policy: version 1.14.0 only
  • p11-Kit Project p11-Kit: from 0.23.6, before 0.23.22 (fixed in 0.23.22)

Published 2020-12-16. Last modified 2026-06-17.