CVE-2026-13757

EUVD-2026-40173
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.2 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 4.17%
Affected Products (NVD)
VendorProductVersion
redhathardened_images
-
redhatopenshift_container_platform
4.0 ≤
𝑥
≤ 4.22.1
redhatenterprise_linux
6.0
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux
10.0
p11-kit_projectp11-kit
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
p11-kit
bookworm
postponed
bullseye
postponed
forky
0.26.4-1
fixed
sid
0.26.4-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
p11-kit
bionic
deferred
focal
deferred
jammy
deferred
noble
deferred
questing
ignored
resolute
deferred
trusty
deferred
xenial
deferred
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
p11-kit
RHEL 9
0:0.26.4-1.el9_8
fixed
p11-kit-client
RHEL 9
0:0.26.4-1.el9_8
fixed
p11-kit-devel
RHEL 9
0:0.26.4-1.el9_8
fixed
p11-kit-server
RHEL 9
0:0.26.4-1.el9_8
fixed
p11-kit-trust
RHEL 9
0:0.26.4-1.el9_8
fixed