Описание
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.
Меры по смягчению последствий
This CVE requires same-user access to the p11-kit RPC Unix domain socket (/run/user//p11-kit/pkcs11-*). Any process running as the socket-owning user can trigger the crash without further authentication.
If p11-kit is managed via systemd --user, ensure Restart=on-failure is set in the unit file so that a crash is automatically recovered without manual intervention.
Red Hat recommends updating p11-kit to version 0.26.3 or later, which introduces a recursion depth limit in the RPC attribute parsing and fully addresses this flaw.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | p11-kit | Fix deferred | ||
| Red Hat Enterprise Linux 7 | p11-kit | Fix deferred | ||
| Red Hat Enterprise Linux 8 | p11-kit | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred | ||
| Red Hat Enterprise Linux 10 | p11-kit | Fixed | RHSA-2026:49668 | 03.08.2026 |
| Red Hat Enterprise Linux 9 | p11-kit | Fixed | RHSA-2026:49667 | 03.08.2026 |
| Red Hat Enterprise Linux 9 | p11-kit | Fixed | RHSA-2026:49667 | 03.08.2026 |
| Red Hat Hardened Images | p11-kit-main-0.26.2-1.2.hum1 | Fixed | RHSA-2026:37469 | 10.07.2026 |
| Red Hat Hardened Images | p11-kit-main-0.26.4-1.hum1 | Fixed | RHSA-2026:38342 | 12.07.2026 |
| Red Hat Insights proxy 1.5 | insights-proxy/insights-proxy-container-rhel9 | Fixed | RHSA-2026:53371 | 11.08.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.2 Medium
CVSS3
Связанные уязвимости
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.
P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing
A flaw was found in p11-kit. The RPC message attribute parsing functio ...
EPSS
6.2 Medium
CVSS3