CVE-2020-36332: Debian Linux
High severity, CVSS 7.5. EPSS: 2% chance of exploitation in the next 30 days.
A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.
Affected products
- Debian Debian Linux: version 10.0 only
- Netapp Ontap Select Deploy Administration Utility: affected versions not specified
- Red Hat Enterprise Linux: version 8.0 only
- Webmproject Libwebp: before 1.0.1 (fixed in 1.0.1)
Published 2021-05-21. Last modified 2026-06-17.