CVE-2026-40253Disclosure(opencryptoki_project / opencryptoki)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch opencryptoki_project opencryptoki systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. In versions 3.26.0 and below, the BER/DER decoding functions in the shared common library (asn1.c) accept a raw pointer but no buffer length parameter, and trust attacker-controlled BER length fields without validating them against actual buffer boundaries. All primitive decoders are affected: ber_decode_INTEGER, ber_decode_SEQUENCE, ber_decode_OCTET_STRING, ber_decode_BIT_STRING, and ber_decode_CHOICE. Additionally, ber_decode_INTEGER can produce integer underflows when the encoded length is zero. An attacker supplying a malformed BER-encoded cryptographic object through PKCS#11 operations such as C_CreateObject or C_UnwrapKey, token loading from disk, or remote backend communication can trigger out-of-bounds reads. This affects all token backends (Soft, ICA, CCA, TPM, EP11, ICSF) since the vulnerable code is in the shared common library. A patch is available thorugh commit ed378f463ef73364c89feb0fc923f4dc867332a3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opencryptoki

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-17); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
opencryptoki

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-17: 1Mentions · 2026-06-18: 1Patch / Workaround · 2026-06-18: 1Technical Details · 2026-04-17: 104-1706-18
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-171
Disclosure1
2026-06-181
Patch1
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-40253 openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. In versions 3.26.0 and below, the BER/DER decoding functions in the shared common library (a… https://www.cve.org/CVERecord?id=CVE-2026-40253

    Post summary

    The post identifies CVE‑2026‑40253 as a vulnerability in openCryptoki’s BER/DER decoding functions, but does not provide PoC, exploit code, or mitigation details.

    0001181
    57.2K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🛡️ Vulnerabilidade CVE-2026-40253 no opencryptoki: saiba como proteger seu #Oracle Linux 8. Comandos para verificar, script de atualização automática e alternativas de mitigação. Saiba mais: -> http://tinyurl.com/3rv2wy3k https://t.co/UdQiZnrRLs

    Post summary

    The tweet offers a safeguard for CVE‑2026‑40253 by providing an auto‑update script and mitigation steps for Oracle Linux 8.

    1000057
    1.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopencryptoki_projectopencryptoki---

Explore more