Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-13757

Опубликовано: 29 июн. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.2

Описание

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

РелизСтатусПримечание
devel

deferred

2026-06-30
esm-infra-legacy/trusty

deferred

2026-06-30
esm-infra-legacy/xenial

deferred

2026-06-30
esm-infra/bionic

deferred

2026-06-30
esm-infra/focal

deferred

2026-06-30
jammy

deferred

2026-06-30
noble

deferred

2026-06-30
questing

ignored

end of life, was deferred [2026-06-30]
resolute

deferred

2026-06-30
upstream

needs-triage

Показывать по

EPSS

Процентиль: 3%
0.00136
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
redhat
около 2 месяцев назад

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

CVSS3: 6.2
nvd
около 1 месяца назад

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

msrc
около 1 месяца назад

P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing

CVSS3: 6.2
debian
около 1 месяца назад

A flaw was found in p11-kit. The RPC message attribute parsing functio ...

CVSS3: 6.2
github
около 1 месяца назад

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

EPSS

Процентиль: 3%
0.00136
Низкий

6.2 Medium

CVSS3