A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.
CVSS Details
- CVSS 3.1 Base Score: 6.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | Upgrade p11-kit-develUpgrade p11-kit-trust-debuginfoUpgrade p11-kitUpgrade p11-kit-trustUpgrade p11-kit-clientUpgrade p11-kit-debugsourceUpgrade p11-kit-server-debuginfoNo solution existsUpgrade p11-kit-debuginfoUpgrade p11-kit-client-debuginfoUpgrade p11-kit-server | Jul 17, 2026 | Jun 23, 2026 |
| Rocky_linux | — | Upgrade p11-kit-develUpgrade p11-kit-clientUpgrade p11-kit-server-debuginfoUpgrade p11-kit-debuginfoUpgrade p11-kit-debugsourceUpgrade p11-kit-client-debuginfoUpgrade p11-kit-trust-debuginfoUpgrade p11-kit-trustUpgrade p11-kit-serverUpgrade p11-kit | Aug 6, 2026 | Aug 4, 2026 |
| Ubuntu | — | Upgrade p11-kit-modulesUpgrade p11-kit (Ubuntu Pro)Upgrade p11-kit-modules (Ubuntu Pro)Upgrade p11-kitUpgrade libp11-kit0Upgrade libp11-kit0 (Ubuntu Pro) | Aug 30, 2026 | Aug 27, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub