Source: p11-kit Version: 0.26.4-1 Severity: important Tags: security upstream Forwarded: https://github.com/p11-glue/p11-kit/pull/777 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for p11-kit. CVE-2026-18938[0]: | A flaw was found in p11-kit. A local attacker, or one with | equivalent access to a reachable RPC channel, could exploit an | integer overflow vulnerability. By sending specially crafted | messages, the attacker can cause the system to miscalculate memory | allocation for nested attributes. This leads to a memory corruption | issue, specifically a heap out-of-bounds write, which can crash the | p11-kit RPC parsing process, resulting in a Denial of Service (DoS). | This vulnerability is only exploitable on 32 bit systems. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-18938 https://www.cve.org/CVERecord?id=CVE-2026-18938 [1] https://github.com/p11-glue/p11-kit/pull/777 [2] https://github.com/p11-glue/p11-kit/commit/3e64244e538550c6a7fcf826fa8c50a4604416dc Please adjust the affected versions in the BTS as needed. Regards, Salvatore

