Description
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected products
- p11-kit_project / p11-kit
- redhat / enterprise_linux6.0 – 6.0
- redhat / enterprise_linux7.0 – 7.0
- redhat / enterprise_linux8.0 – 8.0
- redhat / enterprise_linux9.0 – 9.0
- redhat / enterprise_linux10.0 – 10.0
- redhat / hardened_images
- redhat / openshift_container_platform4.0 – 4.22.1
References
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:37469
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:38342
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:49667
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:49668
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:53371
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:54387
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:54760
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:58981
- VENDOR_ADVISORYhttps://access.redhat.com/security/cve/CVE-2026-13757
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=2494556
- VENDOR_ADVISORYhttps://github.com/advisories/GHSA-p2wm-69qx-x25w
Updated 17m ago · 8 sources