Uncontrolled Recursion Affecting p11-kit-server package, versions <0:0.26.4-1.el10_2


Severity

Recommended
0.0
medium
0
10

Based on Oracle Linux security rating.

Threat Intelligence

EPSS
0.15% (5th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ORACLE10-P11KITSERVER-18512291
  • published3 Aug 2026
  • disclosed29 Jun 2026

Introduced: 29 Jun 2026

CVE-2026-13757  (opens in a new tab)
CWE-674  (opens in a new tab)

How to fix?

Upgrade Oracle:10 p11-kit-server to version 0:0.26.4-1.el10_2 or higher.
This issue was patched in ELSA-2026-49668.

NVD Description

Note: Versions mentioned in the description apply only to the upstream p11-kit-server package and not the p11-kit-server package as distributed by Oracle. See How to fix? for Oracle:10 relevant fixed versions and status.

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

CVSS Base Scores

version 3.1