CVE-2026-2100
published 2026-03-26CVE-2026-2100: A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.16%
63.9th percentile
A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | p11-kit | < p11-kit 0.26.2-2 (forky) | p11-kit 0.26.2-2 (forky) |
| p11-glue | p11-kit | < 0.26.2 | 0.26.2 |
| p11-kit_project | p11-kit | >= 0 < 0.26.2-2 | 0.26.2-2 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv5.3MEDIUM
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
p11-kit: p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters
vendor_redhat·2026-02-06·CVSS 5.3
CVE-2026-2100 [MEDIUM] CWE-824 p11-kit: p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters
p11-kit: p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters
A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.
A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to retur
Debian
CVE-2026-2100: p11-kit - A flaw was found in p11-kit. A remote attacker could exploit this vulnerability ...
vendor_debian·2026·CVSS 5.3
CVE-2026-2100 [MEDIUM] CVE-2026-2100: p11-kit - A flaw was found in p11-kit. A remote attacker could exploit this vulnerability ...
A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 0.26.2-2)
sid: resolved (fixed in 0.26.2-2)
trixie: resolved
OSV
CVE-2026-2100: A flaw was found in p11-kit
osv·2026-03-26·CVSS 5.3
CVE-2026-2100 [MEDIUM] CVE-2026-2100: A flaw was found in p11-kit
A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.
GHSA
GHSA-hq85-3f6c-jx84: A flaw was found in p11-kit
ghsa_unreviewed·2026-03-26
CVE-2026-2100 [MEDIUM] CWE-824 GHSA-hq85-3f6c-jx84: A flaw was found in p11-kit
A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.
OSV
CVE-2026-2100: [NULL dereference via C_DeriveKey with specific NULL parameters]
osv·2026-02-09·CVSS 5.3
CVE-2026-2100 [MEDIUM] CVE-2026-2100: [NULL dereference via C_DeriveKey with specific NULL parameters]
[NULL dereference via C_DeriveKey with specific NULL parameters]
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-2100 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-2100 [MEDIUM] CVE-2026-2100 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2100 :
Linux Debian vulnerability analysis and mitigation
A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.
Source : NVD
## 5.3
Score
Published March 26, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Linux Debian
Linux Fedora
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile
Wiz
CVE-2020-37140 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.4
CVE-2020-37140 [HIGH] CVE-2020-37140 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2020-37140 :
FinalWire AIDA64 vulnerability analysis and mitigation
Everest, later referred to as AIDA64, 5.50.2100 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating file open functionality. Attackers can generate a 450-byte buffer of repeated characters and paste it into the file open dialog to trigger an application crash.
Source : NVD
## 4.6
Score
Published February 5, 2026
Severity MEDIUM
CNA Score 4.6
Affected Technologies
FinalWire AIDA64
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:aida64:aida64
Sources
Windows Severity M
Bugzilla
CVE-2026-2100 p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters
bugzilla·2026-02-06·CVSS 5.3
CVE-2026-2100 [MEDIUM] CVE-2026-2100 p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters
CVE-2026-2100 p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters
Summary: potential NULL dereference in p11-kit when calling C_DeriveKey remotely with specific parameters.
Requirements to exploit: if an attacker calls C_DeriveKey on a remote token with either mechanism IBM kyber or IBM btc derive, with specific mechanism parameter values set to NULL. The RPC-client might attempt to return an uninitialized value potentially resulting in a NULL dereference or undefined behavior.
A slight overhaul of p11_rpc_buffer_get_ibm_kyber_mech_param_update and p11_rpc_buffer_get_ibm_btc_derive_mech_param_update functions where variable data could potentially be used uninitialized.
Report from static analysis:
1. Defect type: UNINIT
1. p11-kit-0.26.1/p11-kit/rpc-message.c:1706
https://access.redhat.com/errata/RHSA-2026:18143https://access.redhat.com/errata/RHSA-2026:18599https://access.redhat.com/errata/RHSA-2026:21275https://access.redhat.com/errata/RHSA-2026:22634https://access.redhat.com/errata/RHSA-2026:27998https://access.redhat.com/errata/RHSA-2026:7065https://access.redhat.com/security/cve/CVE-2026-2100https://bugzilla.redhat.com/show_bug.cgi?id=2437308https://github.com/p11-glue/p11-kit/pull/740https://github.com/p11-glue/p11-kit/releases/tag/0.26.2
2026-03-26
Published