VDB
GCVE-VVD-MAGEIA-2021-41
GCVE-VVD-MAGEIA-2021-41
Advisory Published
Multiple integer overflows have been discovered in the array allocations in
the p11-kit library and the p11-kit list command, where overflow checks are
missing before calling realloc or calloc (CVE-2020-29361).
A heap-based buffer over-read has been discovered in the RPC protocol used by
the p11-kit server/remote commands and the client library. When the remote
entity supplies a byte array through a serialized PKCS#11 function call, the
receiving entity may allow the reading of up to 4 bytes of memory past the
heap allocation (CVE-2020-29362).
A heap-based buffer overflow has been discovered in the RPC protocol used by
p11-kit server/remote commands and the client library. When the remote entity
supplies a serialized byte array in a CK_ATTRIBUTE, the receiving entity may
not allocate sufficient length for the buffer to store the deserialized value
(CVE-2020-29363).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | sddm | 0 (affected), 0.19.0-15.1.mga8 (unaffected) | — |
| Mageia | p11-kit | 0 (affected), 0.23.22-1.mga7 (unaffected), 0 (affected), 0.23.22-1.mga7 (unaffected) | — |
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.