CVE-2026-13757Disclosure(p11-kit_project / enterprise_linux)

LOWCVSS 6.2 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-674

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • hardened_images
  • openshift_container_platform
  • p11-kit

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Products
enterprise_linuxhardened_imagesopenshift_container_platformp11-kit

6 versions affected across 4 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-29: 2Technical Details · 2026-06-29: 106-29
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-13757 A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutual… https://www.cve.org/CVERecord?id=CVE-2026-13757 ----- Traducción: Se encontró una fa… http://infoflow.cloud`

    Post summary

    The text announces the discovery of CVE‑2026‑13757 in p11‑kit but provides no evidence of exploit code, active exploitation, patching guidance, or detailed technical data.

    0000038
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-13757 A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutual… https://www.cve.org/CVERecord?id=CVE-2026-13757

    Post summary

    A flaw is disclosed in p11-kit’s RPC message attribute parsing functions, but the post does not provide evidence of exploitation, PoC, or mitigation.

    00000699
    57.7K followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Appp11-kit_projectp11-kit---
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux6.0--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--
Appredhathardened_images---
Appredhatopenshift_container_platform---

Explore more