VYPR

rpm package

almalinux/p11-kit-client

pkg:rpm/almalinux/p11-kit-client

Vulnerabilities (2)

  • CVE-2026-13757MedJun 29, 2026
    affected < 0.26.4-1.el9_8fixed 0.26.4-1.el9_8

    A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLAT

  • CVE-2026-2100MedMar 26, 2026
    affected < 0.26.2-1.el10fixed 0.26.2-1.el10

    A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialize