CVE-2020-36430: Fedoraproject Fedora

High severity, CVSS 7.8. EPSS: 1.1% chance of exploitation in the next 30 days.

libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer data type is used for subtraction.

Affected products

Published 2021-07-20. Last modified 2026-06-17.