Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
This update includes the following RPMs: p11-kit: * mingw32-p11-kit-0.26.2-1.2.hum1 (noarch) * mingw64-p11-kit-0.26.2-1.2.hum1 (noarch) * p11-kit-0.26.2-1.2.hum1 (aarch64, x86_64) * p11-kit-client-0.26.2-1.2.hum1 (aarch64, x86_64) * p11-kit-devel-0.26.2-1.2.hum1 (aarch64, x86_64) * p11-kit-server-0.26.2-1.2.hum1 (aarch64, x86_64) * p11-kit-trust-0.26.2-1.2.hum1 (aarch64, x86_64) * p11-kit-0.26.2-1.2.hum1.src (src) Security Fix(es): p11-kit: * CVE-2026-13757
AI Analysis
Technical Summary
CVE-2026-13757 is a vulnerability in the p11-kit package, specifically in the RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value(). These functions form a mutually-recursive call chain without a recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services. The vulnerability requires same-user access to the Unix domain socket and does not require further authentication. Red Hat recommends updating to p11-kit version 0.26.3 or later, which implements a recursion depth limit to mitigate this issue.
Potential Impact
The vulnerability allows an unauthenticated local attacker with access to the p11-kit RPC Unix domain socket to cause a denial of service by crashing the p11-kit server process through stack exhaustion. This crash also affects dependent services such as SSH agents, VPN clients, and browsers, potentially disrupting normal operations. There is no impact on confidentiality or integrity reported. The attack complexity is low, and no privileges or user interaction are required beyond local same-user socket access.
Mitigation Recommendations
Red Hat recommends updating p11-kit to version 0.26.3 or later, which introduces a recursion depth limit in the RPC attribute parsing and fully addresses this vulnerability. If p11-kit is managed via systemd --user, ensure the unit file has 'Restart=on-failure' set to automatically recover from crashes. Since the vulnerability requires same-user access to the Unix domain socket, restricting access to this socket can reduce risk. Patch status is confirmed as fixed in version 0.26.3 and later.
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
Description
This update includes the following RPMs: p11-kit: * mingw32-p11-kit-0.26.2-1.2.hum1 (noarch) * mingw64-p11-kit-0.26.2-1.2.hum1 (noarch) * p11-kit-0.26.2-1.2.hum1 (aarch64, x86_64) * p11-kit-client-0.26.2-1.2.hum1 (aarch64, x86_64) * p11-kit-devel-0.26.2-1.2.hum1 (aarch64, x86_64) * p11-kit-server-0.26.2-1.2.hum1 (aarch64, x86_64) * p11-kit-trust-0.26.2-1.2.hum1 (aarch64, x86_64) * p11-kit-0.26.2-1.2.hum1.src (src) Security Fix(es): p11-kit: * CVE-2026-13757
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-13757 is a vulnerability in the p11-kit package, specifically in the RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value(). These functions form a mutually-recursive call chain without a recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services. The vulnerability requires same-user access to the Unix domain socket and does not require further authentication. Red Hat recommends updating to p11-kit version 0.26.3 or later, which implements a recursion depth limit to mitigate this issue.
Potential Impact
The vulnerability allows an unauthenticated local attacker with access to the p11-kit RPC Unix domain socket to cause a denial of service by crashing the p11-kit server process through stack exhaustion. This crash also affects dependent services such as SSH agents, VPN clients, and browsers, potentially disrupting normal operations. There is no impact on confidentiality or integrity reported. The attack complexity is low, and no privileges or user interaction are required beyond local same-user socket access.
Mitigation Recommendations
Red Hat recommends updating p11-kit to version 0.26.3 or later, which introduces a recursion depth limit in the RPC attribute parsing and fully addresses this vulnerability. If p11-kit is managed via systemd --user, ensure the unit file has 'Restart=on-failure' set to automatically recover from crashes. Since the vulnerability requires same-user access to the Unix domain socket, restricting access to this socket can reduce risk. Patch status is confirmed as fixed in version 0.26.3 and later.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:37469
- Cve Count
- 1
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a50ba3568715ace4357d420
Added to database: 07/10/2026, 09:24:05 UTC
Last enriched: 08/13/2026, 19:36:05 UTC
Last updated: 09/15/2026, 03:19:31 UTC
Views: 153
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.