Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-13757

Опубликовано: 29 июн. 2026
Источник: nvd
CVSS3: 6.2
EPSS Низкий

Описание

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:*
Версия от 4.0 (включая) до 4.22.1 (включая)
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:p11-kit_project:p11-kit:-:*:*:*:*:*:*:*

EPSS

Процентиль: 3%
0.00136
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-674

Связанные уязвимости

CVSS3: 6.2
ubuntu
около 1 месяца назад

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

CVSS3: 6.2
redhat
около 2 месяцев назад

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

msrc
около 1 месяца назад

P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing

CVSS3: 6.2
debian
около 1 месяца назад

A flaw was found in p11-kit. The RPC message attribute parsing functio ...

rocky
8 дней назад

Moderate: p11-kit security update

EPSS

Процентиль: 3%
0.00136
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-674