cbcvebase.
CVE-2020-28928
published 2020-11-24

CVE-2020-28928: In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid…

PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.64%
46.8th percentile
In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid write access (buffer overflow).

Affected

15 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianmusl< musl 1.2.2-1 (bookworm)musl 1.2.2-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
musl-libcmusl<= 1.2.1
musl-libcmusl>= 0 < 1.2.2-11.2.2-1
musl-libcmusl>= 0 < 1.2.2-11.2.2-1
musl-libcmusl>= 0 < 1.2.2-11.2.2-1
musl-libcmusl>= 0 < 1.2.2-11.2.2-1
musl-libcmusl>= 0 < 0.9.15-1ubuntu0.1~esm20.9.15-1ubuntu0.1~esm2
musl-libcmusl>= 0 < 1.1.9-1ubuntu0.1~esm31.1.9-1ubuntu0.1~esm3
musl-libcmusl>= 0 < 1.1.19-1ubuntu0.1~esm11.1.19-1ubuntu0.1~esm1
musl-libcmusl>= 0 < 1.1.24-1ubuntu0.1~esm11.1.24-1ubuntu0.1~esm1
oraclegraalvm
oraclegraalvm

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian5.5MEDIUM
vendor_oracle5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.