CVE-2026-13757
MEDIUMCVSS v3.1: 6.2 · EPSS: 0.0013 (3.1 percentile)
Source data as of:
At a glance
- Severity
- MEDIUM
- CVSS
- 6.2 v3.1 · NVD
- EPSS
- 0.0013 (3.1 percentile) · FIRST.org
- CISA KEV
- No
- Type
- Uncontrolled Recursion · NVD CWE
- Attack conditions (CVSS vector)
- No privilegesNo user interaction · Source: NVD Vector
- Affected vendors
- p11-kit_project, redhat
- Published
- 2026-06-29 · Modified: 2026-07-11
- References
- Jump to references (4)
CVSS / EPSS / KEV
Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources
Description
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.
References
Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.