Junglewise Threat Intelligence

CVE-2026-2100: p11-kit NULL dereference in C_DeriveKey RPC handling

CVE-2026-2100 · Severity: medium · CVSS 5.3 · Published 2026-03-26

Technologies: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9. Vendors: Red Hat.

Executive brief

p11-kit is a library used to coordinate and manage PKCS#11 security modules, which handle cryptographic operations and digital certificates. A flaw in how it processes certain remote requests could allow an attacker to crash applications using the library. This results in a denial-of-service condition, potentially disrupting secure communications or authentication services.

Technical details

A vulnerability exists in p11-kit due to the access of uninitialized pointers (CWE-824) within the RPC message handling component. Specifically, the functions p11_rpc_buffer_get_ibm_kyber_mech_param_update and p11_rpc_buffer_get_ibm_btc_derive_mech_param_update in rpc-message.c fail to initialize the 'data' variable under certain conditions. A remote attacker can trigger this by calling the C_DeriveKey function on a remote token using IBM Kyber or IBM BTC derive mechanisms with specific parameters set to NULL. This leads to a NULL dereference or the use of uninitialized memory during memcpy operations, causing a denial of service (DoS) or unpredictable system states. A patch is available in p11-kit version 0.26.2 and via Red Hat security updates.

Affected products

  • p11-glue p11-kit 0.26.1
  • Red Hat Enterprise Linux 10 10.0
  • Red Hat Enterprise Linux 9 9.0

Timeline

  • 2026-02-06: other: Vulnerability reported via Red Hat Bugzilla
  • 2026-03-26: disclosed: Initial public disclosure and CVE assignment
  • 2026-03-26: patched: Fix submitted via GitHub pull request 740
  • 2026-05-19: advisory: Red Hat issued security advisory RHSA-2026:18143

References