PT-2026-53679 · P11 Kit+1 · P11-Kit+1

·

CVE-2026-13757

·

Published

2026-06-29

·

Updated

2026-08-27

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions p11-kit (affected versions not specified)
Description A flaw exists in the RPC message attribute parsing process. The functions p11 rpc message get attribute() and p11 rpc message get attribute array value() create a mutually-recursive call chain that lacks a recursion depth limit when handling nested CKA WRAP TEMPLATE, CKA UNWRAP TEMPLATE, and CKA DERIVE TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can trigger stack exhaustion—a condition where the program's call stack overflows—by sending a specially crafted request with deeply nested template attributes, resulting in the crash of the p11-kit server process and its dependent services.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:49667
ALSA-2026:49668
AZL-91743
CVE-2026-13757
ECHO-E3A5-7704-649F
RHSA-2026:37469
RHSA-2026:38342
RHSA-2026:49667
RHSA-2026:49668
USN-8687-1

Affected Products

Rocky Linux
P11-Kit