CVE-2026-13757
published 2026-06-29CVE-2026-13757: A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a…
PriorityP428medium6.2CVSS 3.1
AVLACLPRNUINSUCNINAH
EPSS
0.14%
3.5th percentile
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| p11-kit_project | p11-kit | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | 4.0 – 4.22.1 | — |
CVSS provenance
nvdv3.16.2MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Red Hat OpenShift Container Platform 4 p11-kit p11_rpc_message_get_attribute recursion
vuldb·2026-06-30·CVSS 6.2
CVE-2026-13757 [MEDIUM] Red Hat OpenShift Container Platform 4 p11-kit p11_rpc_message_get_attribute recursion
A vulnerability was found in Red Hat Enterprise Linux 10, Enterprise Linux 6, Enterprise Linux 7, Enterprise Linux 8, Enterprise Linux 9, Hardened Images and OpenShift Container Platform 4. It has been rated as problematic. The impacted element is the function p11_rpc_message_get_attribute of the component p11-kit. This manipulation of the argument CKA_WRAP_TEMPLATE/CKA_UNWRAP_TEMPLATE/CKA_DERIVE_TEMPLATE causes uncontrolled recursion.
The identification of this vulnerability is CVE-2026-13757. The attack can only be executed locally. There is no exploit available.
GHSA
A flaw was found in p11-kit.
ghsa_unreviewed·2026-06-29
CVE-2026-13757 [MEDIUM] CWE-674 A flaw was found in p11-kit.
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.
Red Hat
p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing
vendor_redhat·2026-06-23·CVSS 6.2
CVE-2026-13757 [MEDIUM] CWE-674 p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing
p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.
Package: p11-kit (Red Hat Enterprise Linux 10) - Fix deferred
Package: p11-kit (Red Hat Enterprise Linux 6) - Fix deferred
Package: p11-kit (Red Hat
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-13757 p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing [fedora-all]
bugzilla·2026-06-29·CVSS 6.2
CVE-2026-13757 [MEDIUM] CVE-2026-13757 p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing [fedora-all]
CVE-2026-13757 p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() in p11-kit/rpc-message.c form a mutually-recursive call chain with no depth limit when processing CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attribute types. Similarly, proto_read_attribute_buffer_array() in p11-kit/rpc-server.c recurses without bound for IS_ATTRIBUTE_ARRAY types.
An attacker wh
Bugzilla
CVE-2026-13757 p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing
bugzilla·2026-06-29·CVSS 6.2
CVE-2026-13757 [MEDIUM] CVE-2026-13757 p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing
CVE-2026-13757 p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() in p11-kit/rpc-message.c form a mutually-recursive call chain with no depth limit when processing CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attribute types. Similarly, proto_read_attribute_buffer_array() in p11-kit/rpc-server.c recurses without bound for IS_ATTRIBUTE_ARRAY types.
An attacker who can connect to the p11-kit RPC server via Unix domain socket (/run/user//p11-kit/pkcs11-*) can send a specially crafted C_CreateObject request with deeply nested template attributes (~50,000 levels, ~650KB wire data), causing stack exha
2026-06-29
Published