Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 10

Количество 10

ubuntu логотип

CVE-2026-13757

около 1 месяца назад

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2026-13757

около 2 месяцев назад

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

CVSS3: 6.2
EPSS: Низкий
nvd логотип

CVE-2026-13757

около 1 месяца назад

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

CVSS3: 6.2
EPSS: Низкий
msrc логотип

CVE-2026-13757

около 1 месяца назад

P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing

EPSS: Низкий
debian логотип

CVE-2026-13757

около 1 месяца назад

A flaw was found in p11-kit. The RPC message attribute parsing functio ...

CVSS3: 6.2
EPSS: Низкий
rocky логотип

RLSA-2026:49668

8 дней назад

Moderate: p11-kit security update

EPSS: Низкий
rocky логотип

RLSA-2026:49667

8 дней назад

Moderate: p11-kit security update

EPSS: Низкий
github логотип

GHSA-p2wm-69qx-x25w

около 1 месяца назад

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

CVSS3: 6.2
EPSS: Низкий
oracle-oval логотип

ELSA-2026-49668

9 дней назад

ELSA-2026-49668: p11-kit security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-49667

8 дней назад

ELSA-2026-49667: p11-kit security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-13757

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

CVSS3: 6.2
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-13757

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

CVSS3: 6.2
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-13757

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

CVSS3: 6.2
0%
Низкий
около 1 месяца назад
msrc логотип
CVE-2026-13757

P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing

0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-13757

A flaw was found in p11-kit. The RPC message attribute parsing functio ...

CVSS3: 6.2
0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:49668

Moderate: p11-kit security update

0%
Низкий
8 дней назад
rocky логотип
RLSA-2026:49667

Moderate: p11-kit security update

0%
Низкий
8 дней назад
github логотип
GHSA-p2wm-69qx-x25w

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

CVSS3: 6.2
0%
Низкий
около 1 месяца назад
oracle-oval логотип
ELSA-2026-49668

ELSA-2026-49668: p11-kit security update (MODERATE)

0%
Низкий
9 дней назад
oracle-oval логотип
ELSA-2026-49667

ELSA-2026-49667: p11-kit security update (MODERATE)

0%
Низкий
8 дней назад

Уязвимостей на страницу