CVE-2026-2100Disclosure(p11-kit_project / enterprise_linux)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch p11-kit_project enterprise_linux systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-824

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • hardened_images
  • p11-kit

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-26); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
enterprise_linuxhardened_imagesp11-kit

3 versions affected across 3 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-26: 1Mentions · 2026-07-19: 1Mentions · 2026-08-02: 1Patch / Workaround · 2026-08-02: 1Technical Details · 2026-03-26: 103-2607-1908-02
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-261
Disclosure1
2026-07-191
Disclosure1
2026-08-021
Patch1
Full discourse3 posts
  • MalwareObserver@MalwareObserver
    Patch

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-2100](https://access.redhat.com/errata/RHSA-2026:18143) A flaw was found in p11-kit. A ... https://access.redhat.com/errata/RHSA-2026:18143 #PatchManagement #Vulnerability #CVE

    Post summary

    Red Hat announced CVE‑2026‑2100 impacting p11‑kit and released a patch via RHSA‑2026:18143; no proof‑of‑concept or exploitation reports were disclosed.

    0000041
    18 followersView on X
  • MalwareObserver@MalwareObserver
    Disclosure

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-2100](https://access.redhat.com/errata/RHSA-2026:18143) A flaw was found in p11-kit. A ... https://access.redhat.com/errata/RHSA-2026:18143 #Vulnerability #CVE #ZeroDay

    Post summary

    The tweet announces the discovery of CVE‑2026‑2100 in p11‑kit and points to a Red Hat errata page, providing no additional technical or exploit details.

    0000063
    12 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2100 A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc… https://www.cve.org/CVERecord?id=CVE-2026-2100

    Post summary

    The post announces CVE-2026-2100, a remote exploitation flaw in p11‑kit that can be triggered by calling the C_DeriveKey function on IBM kyber or btc token backends.

    00000115
    56.9K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appp11-kit_projectp11-kit---
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux9.0--
Appredhathardened_images---

Explore more