A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no r…
中危 CVSS 6.2
摘要
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhau…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
- :
数据来源
- NVD DATABASE
原始链接
- https://access.redhat.com/errata/RHSA-2026:37469
- https://access.redhat.com/errata/RHSA-2026:38342
- https://access.redhat.com/errata/RHSA-2026:49668
- https://access.redhat.com/security/cve/CVE-2026-13757 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2494556 Issue Tracking
- https://github.com/advisories/GHSA-p2wm-69qx-x25w
时间线
- nvd_ingest NVD