Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-13757— P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

P11-glue P11-kit是P11-glue团队开源的一个用于加载和枚举PKCS模块的工具软件。 P11-glue P11-kit存在资源管理错误漏洞,该漏洞源于p11-kit中RPC消息属性解析函数p11_rpc_message_get_attribute()和p11_rpc_message_get_attribute_array_value()处理嵌套CKA_WRAP_TEMPLATE、CKA_UNWRAP_TEMPLATE和CKA_DERIVE_TEMPLATE属性时形成递归调用链且无递归深度

CVSS 6.2 · Medium EPSS 0.20% · P9

Affected Version Matrix 29

VendorProduct Version RangeStatus
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790223279< * unaffected
1790223719< * unaffected
1790272426< * unaffected
1790589998< * unaffected
1790589912< * unaffected
1790589914< * unaffected
1790589855< * unaffected
1790598593< * unaffected
Red Hat Red Hat Discovery 2 1786638573< * unaffected
1786634825< * unaffected
Red Hat Red Hat Enterprise Linux 10 0:0.26.4-1.el10_2< * unaffected
Red Hat Red Hat Enterprise Linux 6 any affected
Red Hat Red Hat Enterprise Linux 7 any affected
Red Hat Red Hat Enterprise Linux 8 any affected
Red Hat Red Hat Enterprise Linux 9 0:0.26.4-1.el9_8< * unaffected
0:0.26.4-1.el9_8< * unaffected
Red Hat Red Hat Hardened Images 0.26.2-1.2.hum1< * unaffected
0.26.4-1.hum1< * unaffected
Red Hat Red Hat Insights proxy 1.5 1786433656< * unaffected
Red Hat Red Hat OpenShift Container Platform 4 any affected
any affected
Red Hat Red Hat Update Infrastructure 5 1786435241< * unaffected
1786533457< * unaffected
1786533449< * unaffected
1786435483< * unaffected
1786533529< * unaffected
1787241211< * unaffected
1787135742< * unaffected
1787241260< * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-13757

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未经控制的递归
Source: CVE Program / CVE List V5
Vulnerability Title
P11-glue P11-kit 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
P11-glue P11-kit是P11-glue团队开源的一个用于加载和枚举PKCS模块的工具软件。 P11-glue P11-kit存在资源管理错误漏洞,该漏洞源于p11-kit中RPC消息属性解析函数p11_rpc_message_get_attribute()和p11_rpc_message_get_attribute_array_value()处理嵌套CKA_WRAP_TEMPLATE、CKA_UNWRAP_TEMPLATE和CKA_DERIVE_TEMPLATE属性时形成递归调用链且无递归深度
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 0:0.26.4-1.el10_2 ~ * cpe:/o:redhat:enterprise_linux:10.2
Red Hat Red Hat Enterprise Linux 9 0:0.26.4-1.el9_8 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9 0:0.26.4-1.el9_8 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790223279 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790223719 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790272426 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790589998 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790589912 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790589914 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790589855 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790598593 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Red Hat Discovery 2 1786638573 ~ * cpe:/a:redhat:discovery:2::el9
Red Hat Red Hat Discovery 2 1786634825 ~ * cpe:/a:redhat:discovery:2::el9
Red Hat Red Hat Hardened Images 0.26.2-1.2.hum1 ~ * cpe:/a:redhat:hummingbird:1
Red Hat Red Hat Hardened Images 0.26.4-1.hum1 ~ * cpe:/a:redhat:hummingbird:1
Red Hat Red Hat Insights proxy 1.5 1786433656 ~ * cpe:/a:redhat:insights_proxy:1.5::el9
Red Hat Red Hat Update Infrastructure 5 1786435241 ~ * cpe:/a:redhat:rhui:5::el9
Red Hat Red Hat Update Infrastructure 5 1786533457 ~ * cpe:/a:redhat:rhui:5::el9
Red Hat Red Hat Update Infrastructure 5 1786533449 ~ * cpe:/a:redhat:rhui:5::el9
Red Hat Red Hat Update Infrastructure 5 1786435483 ~ * cpe:/a:redhat:rhui:5::el9
Red Hat Red Hat Update Infrastructure 5 1786533529 ~ * cpe:/a:redhat:rhui:5::el9
Red Hat Red Hat Update Infrastructure 5 1787241211 ~ * cpe:/a:redhat:rhui:5::el9
Red Hat Red Hat Update Infrastructure 5 1787135742 ~ * cpe:/a:redhat:rhui:5::el9
Red Hat Red Hat Update Infrastructure 5 1787241260 ~ * cpe:/a:redhat:rhui:5::el9
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4

II. Public POCs for CVE-2026-13757

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-13757

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-13757 (18)

Same Patch Batch · Red Hat · 2026-06-29 · 7 CVEs total

CVE-2026-12856 8.8 HIGH Vscode-java: vscode: command injection vulnerability in the javadoc hover provider of the
CVE-2026-12912 7.3 HIGH Libtiff: libtiff: heap-based buffer overflow via crafted pixarlog-compressed tiff image
CVE-2026-13601 7.1 HIGH Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclos
CVE-2026-13595 6.8 MEDIUM Util-linux: util-linux: heap use-after-free in libblkid nested partition probing
CVE-2026-57965 5.1 MEDIUM Spice-vdagent: integer overflow in udscs_write() leading to heap buffer overflow
CVE-2026-57966 4.4 MEDIUM Spice-vdagent: path traversal in file transfer via unsanitized filename

IV. Related Vulnerabilities

V. Comments for CVE-2026-13757

No comments yet


Leave a comment