yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2021-32292
Component Overview
Vulnerability Overview
Name
CVE-2021-32292
Source
NVD (
link
)
Debian (
link
)
Description
An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit.
CWEs
CWE-787
Published Date
Aug 22, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/json-c/json-c/issues/654
Exploit
https://security.netapp.com/advisory/ntap-20230929-0010/
Third Party Advisory
https://www.debian.org/security/2023/dsa-5486
Third Party Advisory
https://github.com/json-c/json-c/issues/654
Exploit
https://security.netapp.com/advisory/ntap-20230929-0010/
Third Party Advisory
https://www.debian.org/security/2023/dsa-5486
Third Party Advisory
Analysis
#
Affected Component
Analysis
json-c
Patched
Vulnerability Ratings
#
9.8
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
json-c
buildroot
2025.02.x
0.18
Not Affected
json-c
buildroot
master
0.18
Not Affected
libjson-c
openwrt
master
0.18-r1
Not Affected
libjson-c
openwrt
openwrt-25.12
0.18-r1
Not Affected
json-c
yocto
master
0.18
Not Affected
json-c
yocto
scarthgap
0.17
Not Affected
Resolved with patches
#
json-c (yocto:kirkstone)
#
Title
Author
Resolve
1
Fix read past end of buffer
Marc <34656315+MarcT512@users.noreply.github.com>
CVE-2021-32292