PT-2026-53679 · P11 Kit+1 · P11-Kit+1
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
p11-kit (affected versions not specified)
Description
A flaw exists in the RPC message attribute parsing process. The functions
p11 rpc message get attribute() and p11 rpc message get attribute array value() create a mutually-recursive call chain that lacks a recursion depth limit when handling nested CKA WRAP TEMPLATE, CKA UNWRAP TEMPLATE, and CKA DERIVE TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can trigger stack exhaustion—a condition where the program's call stack overflows—by sending a specially crafted request with deeply nested template attributes, resulting in the crash of the p11-kit server process and its dependent services.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rocky Linux
P11-Kit