VYPR
Medium severity5.5NVD Advisory· Published Nov 24, 2020· Updated Jun 17, 2026

CVE-2020-28928

CVE-2020-28928

Description

In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid write access (buffer overflow).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • cpe:2.3:a:musl-libc:musl:*:*:*:*:*:*:*:*
    Range: <=1.2.1
  • cpe:2.3:a:oracle:graalvm:20.3.2:*:*:*:enterprise:*:*:*+ 1 more
    • cpe:2.3:a:oracle:graalvm:20.3.2:*:*:*:enterprise:*:*:*
    • cpe:2.3:a:oracle:graalvm:21.1.0:*:*:*:enterprise:*:*:*
  • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
  • musl libc/musl libcdescription
  • Range: <=1.2.1

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.