Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:18143

Опубликовано: 29 мая 2026
Источник: rocky
Оценка: Moderate

Описание

Moderate: p11-kit security update

The p11-kit packages provide a mechanism to manage PKCS#11 modules. The p11-kit-trust subpackage includes a PKCS#11 trust module that provides certificate anchors and black lists based on configuration files.

Security Fix(es):

  • p11-kit: p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters (CVE-2026-2100)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 10 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
p11-kit-trustaarch641.el10p11-kit-trust-0.26.2-1.el10.aarch64.rpm
p11-kitaarch641.el10p11-kit-0.26.2-1.el10.aarch64.rpm
p11-kit-clientaarch641.el10p11-kit-client-0.26.2-1.el10.aarch64.rpm
p11-kit-clientx86_641.el10p11-kit-client-0.26.2-1.el10.x86_64.rpm
p11-kit-trustx86_641.el10p11-kit-trust-0.26.2-1.el10.x86_64.rpm
p11-kitx86_641.el10p11-kit-0.26.2-1.el10.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.

CVSS3: 5.3
redhat
6 месяцев назад

A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.

CVSS3: 5.3
nvd
4 месяца назад

A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.

msrc
4 месяца назад

P11-kit: p11-kit: null dereference via c_derivekey with specific null parameters

CVSS3: 5.3
debian
4 месяца назад

A flaw was found in p11-kit. A remote attacker could exploit this vuln ...