Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-2100

Опубликовано: 09 фев. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий

Описание

[NULL dereference via C_DeriveKey with specific NULL parameters]

РелизСтатусПримечание
devel

released

0.25.10-1ubuntu1
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

not-affected

code not present
jammy

not-affected

code not present
noble

not-affected

code not present
questing

not-affected

code not present
upstream

released

0.26.2-1

Показывать по

Ссылки на источники

EPSS

Процентиль: 27%
0.00095
Низкий

Связанные уязвимости

CVSS3: 5.3
redhat
около 2 месяцев назад

A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.

debian

[NULL dereference via C_DeriveKey with specific NULL parameters]

CVSS3: 5.3
github
4 дня назад

A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.

EPSS

Процентиль: 27%
0.00095
Низкий