Stanislav Fort discovered an out of bounds read and write issue when decrypting CMS messages that were encrypted using password based encryption.

Source: Debian 11: DLA-4321-1 Addresses Critical Out of Bounds Decrypt Flaw