The append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.3 allows remote attackers to cause a denial of service (out-of-bounds read) by clearing the high bit of the byte after invalid utf-8 encoded data.
git.gnupg.org/cgi-bin/gitweb.cgi?p=libksba.git%3Ba=commit%3Bh=243d12fdec66a4360fbb3e307a046b39b5b4ffc3
www.openwall.com/lists/oss-security/2016/04/29/5
www.openwall.com/lists/oss-security/2016/04/29/8
www.openwall.com/lists/oss-security/2016/05/10/3
www.ubuntu.com/usn/USN-2982-1
security.gentoo.org/glsa/201604-04