CVE-2026-22791
EUVD-2026-241513.01.2026, 19:16
openCryptoki is a PKCS#11 library and tools for Linux and AIX. In 3.25.0 and 3.26.0, there is a heap buffer overflow vulnerability in the CKM_ECDH_AES_KEY_WRAP implementation allows an attacker with local access to cause out-of-bounds writes in the host process by supplying a compressed EC public key and invoking C_WrapKey. This can lead to heap corruption, or denial-of-service.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| opencryptoki_project | opencryptoki | 3.25.0 |
| opencryptoki_project | opencryptoki | 3.26.0 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration