CVE-2026-13757

EUVD-2026-40173
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.2 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 8.19%
Affected Products (NVD)
VendorProductVersion
redhathardened_images
-
redhatopenshift_container_platform
4.0 ≤
𝑥
≤ 4.22.1
redhatenterprise_linux
6.0
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux
10.0
p11-kit_projectp11-kit
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
p11-kit
bookworm
postponed
bullseye
postponed
forky
0.26.5-1
fixed
sid
0.26.5-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
p11-kit
bionic
Fixed 0.23.9-2ubuntu0.1+esm1
released
focal
Fixed 0.23.20-1ubuntu0.1+esm1
released
jammy
Fixed 0.24.0-6ubuntu0.1
released
noble
Fixed 0.25.3-4ubuntu2.2
released
questing
ignored
resolute
needed
trusty
not-affected
xenial
not-affected
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
p11-kit
RHEL 9
0:0.26.4-1.el9_8
fixed
p11-kit-client
RHEL 9
0:0.26.4-1.el9_8
fixed
p11-kit-devel
RHEL 9
0:0.26.4-1.el9_8
fixed
p11-kit-server
RHEL 9
0:0.26.4-1.el9_8
fixed
p11-kit-trust
RHEL 9
0:0.26.4-1.el9_8
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
p11-kit
Azure Linux 3.0
0:0.26.5-1.azl3
fixed