{"id":"CVE-2020-28928","details":"In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid write access (buffer overflow).","modified":"2026-07-08T05:54:00.871994900Z","published":"2020-11-24T18:15:12.207Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:musl-libc:musl:*:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"1.2.1"}],"source":"CPE_RANGE","vendor_product":"musl-libc:musl"},{"vendor_product":"debian:debian_linux","cpes":["cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"9.0"},{"last_affected":"9.0"}],"source":"CPE_STRING"},{"cpes":["cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"33"},{"last_affected":"33"},{"introduced":"34"},{"last_affected":"34"}],"source":"CPE_STRING","vendor_product":"fedoraproject:fedora"}]},"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/r2134abfe847bea7795f0e53756d10a47e6643f35ab8169df8b8a9eb1%40%3Cnotifications.apisix.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r90b60cf49348e515257b4950900c1bd3ab95a960cf2469d919c7264e%40%3Cnotifications.apisix.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/ra63e8dc5137d952afc55dbbfa63be83304ecf842d1eab1ff3ebb29e2%40%3Cnotifications.apisix.apache.org%3E"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKQ3RVSMVZNZNO4D65W2CZZ4DMYFZN2Q/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UW27QVY7ERPTSGKS4KAWE5TU7EJWHKVQ/"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2020/11/20/4"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2020/11/msg00050.html"},{"type":"ADVISORY","url":"https://musl.libc.org/releases.html"},{"type":"FIX","url":"https://www.oracle.com//security-alerts/cpujul2021.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuoct2021.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/graalvm/graalvm-ce-builds","events":[{"introduced":"cf616f9f924f9e60b6158ff4aaed8306382b4c31"},{"last_affected":"a748f59635430848730ca95f41a9f7fa1f26b12b"}],"database_specific":{"source":"CPE_STRING","cpe":["cpe:2.3:a:oracle:graalvm:20.3.2:*:*:*:enterprise:*:*:*","cpe:2.3:a:oracle:graalvm:21.1.0:*:*:*:enterprise:*:*:*"],"extracted_events":[{"introduced":"20.3.2"},{"last_affected":"20.3.2"},{"introduced":"21.1.0"},{"last_affected":"21.1.0"}]}}],"versions":["20.3.2","21.1.0","vm-21.1.0","vm-20.3.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-28928.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}