CVE-2020-29363: Debian Linux
High severity, CVSS 7.5. EPSS: 3.5% chance of exploitation in the next 30 days.
An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the client library. When the remote entity supplies a serialized byte array in a CK_ATTRIBUTE, the receiving entity may not allocate sufficient length for the buffer to store the deserialized value.
Affected products
- Debian Debian Linux: version 10.0 only
- Oracle Communications Cloud Native Core Policy: version 1.14.0 only
- p11-Kit Project p11-Kit: from 0.23.6, before 0.23.22 (fixed in 0.23.22)
Published 2020-12-16. Last modified 2026-06-17.