Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-13757

Опубликовано: 23 июн. 2026
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

Меры по смягчению последствий

This CVE requires same-user access to the p11-kit RPC Unix domain socket (/run/user//p11-kit/pkcs11-*). Any process running as the socket-owning user can trigger the crash without further authentication. If p11-kit is managed via systemd --user, ensure Restart=on-failure is set in the unit file so that a crash is automatically recovered without manual intervention. Red Hat recommends updating p11-kit to version 0.26.3 or later, which introduces a recursion depth limit in the RPC attribute parsing and fully addresses this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6p11-kitFix deferred
Red Hat Enterprise Linux 7p11-kitFix deferred
Red Hat Enterprise Linux 8p11-kitFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Enterprise Linux 10p11-kitFixedRHSA-2026:4966803.08.2026
Red Hat Enterprise Linux 9p11-kitFixedRHSA-2026:4966703.08.2026
Red Hat Enterprise Linux 9p11-kitFixedRHSA-2026:4966703.08.2026
Red Hat Hardened Imagesp11-kit-main-0.26.2-1.2.hum1FixedRHSA-2026:3746910.07.2026
Red Hat Hardened Imagesp11-kit-main-0.26.4-1.hum1FixedRHSA-2026:3834212.07.2026
Red Hat Insights proxy 1.5insights-proxy/insights-proxy-container-rhel9FixedRHSA-2026:5337111.08.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-674
https://bugzilla.redhat.com/show_bug.cgi?id=2494556p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing

EPSS

Процентиль: 3%
0.00136
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
ubuntu
около 1 месяца назад

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

CVSS3: 6.2
nvd
около 1 месяца назад

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

msrc
около 1 месяца назад

P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing

CVSS3: 6.2
debian
около 1 месяца назад

A flaw was found in p11-kit. The RPC message attribute parsing functio ...

rocky
8 дней назад

Moderate: p11-kit security update

EPSS

Процентиль: 3%
0.00136
Низкий

6.2 Medium

CVSS3