Executive brief
p11-kit is a library used to coordinate and manage PKCS#11 security modules, which handle cryptographic operations and digital certificates. A flaw in how it processes certain remote requests could allow an attacker to crash applications using the library. This results in a denial-of-service condition, potentially disrupting secure communications or authentication services.
Technical details
A vulnerability exists in p11-kit due to the access of uninitialized pointers (CWE-824) within the RPC message handling component. Specifically, the functions p11_rpc_buffer_get_ibm_kyber_mech_param_update and p11_rpc_buffer_get_ibm_btc_derive_mech_param_update in rpc-message.c fail to initialize the 'data' variable under certain conditions. A remote attacker can trigger this by calling the C_DeriveKey function on a remote token using IBM Kyber or IBM BTC derive mechanisms with specific parameters set to NULL. This leads to a NULL dereference or the use of uninitialized memory during memcpy operations, causing a denial of service (DoS) or unpredictable system states. A patch is available in p11-kit version 0.26.2 and via Red Hat security updates.
Affected products
- p11-glue p11-kit 0.26.1
- Red Hat Enterprise Linux 10 10.0
- Red Hat Enterprise Linux 9 9.0
Timeline
- 2026-02-06: other: Vulnerability reported via Red Hat Bugzilla
- 2026-03-26: disclosed: Initial public disclosure and CVE assignment
- 2026-03-26: patched: Fix submitted via GitHub pull request 740
- 2026-05-19: advisory: Red Hat issued security advisory RHSA-2026:18143