Medium severity6.2NVD Advisory· Published Jun 29, 2026· Updated Aug 13, 2026
CVE-2026-13757
CVE-2026-13757
Description
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14cpe:2.3:a:p11-kit_project:p11-kit:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:p11-kit_project:p11-kit:-:*:*:*:*:*:*:*
- (no CPE)
- cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:*Range: >=4.0,<=4.22.1
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
- osv-coords5 versionspkg:rpm/almalinux/p11-kitpkg:rpm/almalinux/p11-kit-clientpkg:rpm/almalinux/p11-kit-develpkg:rpm/almalinux/p11-kit-serverpkg:rpm/almalinux/p11-kit-trust
< 0.26.4-1.el9_8+ 4 more
- (no CPE)range: < 0.26.4-1.el9_8
- (no CPE)range: < 0.26.4-1.el9_8
- (no CPE)range: < 0.26.4-1.el9_8
- (no CPE)range: < 0.26.4-1.el9_8
- (no CPE)range: < 0.26.4-1.el9_8
Patches
Vulnerability mechanics
References
10- access.redhat.com/security/cve/CVE-2026-13757nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
- access.redhat.com/errata/RHSA-2026:37469nvd
- access.redhat.com/errata/RHSA-2026:38342nvd
- access.redhat.com/errata/RHSA-2026:49667nvd
- access.redhat.com/errata/RHSA-2026:49668nvd
- access.redhat.com/errata/RHSA-2026:53371nvd
- access.redhat.com/errata/RHSA-2026:54387nvd
- access.redhat.com/errata/RHSA-2026:54760nvd
- github.com/advisories/GHSA-p2wm-69qx-x25wnvd
News mentions
0No linked articles in our index yet.