Skip to content

Integer overflow when allocating memory for arrays of attributes and object identifiers

Moderate
ueno published GHSA-q4r3-hm6m-mvc2 Dec 11, 2020

Package

No package listed

Affected versions

0.21.1 to 0.23.21

Patched versions

0.23.22

Description

Impact

Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or calloc.

Patches

The upstream 0.23.22 release should fix the issue, by using reallocarray more extensively.

Workarounds

None.

References

None.

For more information

If you have any questions or comments about this advisory:

If the questions should be treated confidential, follow our security policy to reach out to us.

Severity

Moderate

CVE ID

CVE-2020-29361

Weaknesses

No CWEs

Credits