#1144476 p11-kit: CVE-2026-18938

Package:
src:p11-kit
Source:
src:p11-kit
Submitter:
Salvatore Bonaccorso
Date:
2026-08-15 17:11:00 UTC
Severity:
normal
Tags:
#1144476#5
Date:
2026-08-15 14:54:21 UTC
From:
To:
Hi,

The following vulnerability was published for p11-kit.

CVE-2026-18938[0]:
| A flaw was found in p11-kit. A local attacker, or one with
| equivalent access to a reachable RPC channel, could exploit an
| integer overflow vulnerability. By sending specially crafted
| messages, the attacker can cause the system to miscalculate memory
| allocation for nested attributes. This leads to a memory corruption
| issue, specifically a heap out-of-bounds write, which can crash the
| p11-kit RPC parsing process, resulting in a Denial of Service (DoS).
| This vulnerability is only exploitable on 32 bit systems.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-18938
https://www.cve.org/CVERecord?id=CVE-2026-18938
[1] https://github.com/p11-glue/p11-kit/pull/777
[2] https://github.com/p11-glue/p11-kit/commit/3e64244e538550c6a7fcf826fa8c50a4604416dc

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1144476#10
Date:
2026-08-15 17:09:36 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
p11-kit, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1144476@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Andreas Metzler <ametzler@debian.org> (supplier of updated p11-kit package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 15 Aug 2026 17:51:12 +0200
Source: p11-kit
Architecture: source
Version: 0.26.5-1
Distribution: unstable
Urgency: medium
Maintainer: Debian GnuTLS Maintainers <pkg-gnutls-maint@lists.alioth.debian.org>
Changed-By: Andreas Metzler <ametzler@debian.org>
Closes: 1144476
Changes:
 p11-kit (0.26.5-1) unstable; urgency=medium
 .
   * New upstream version.
     + rpc: guard against overflow when decoding nested attributes
       (CVE-2026-18938) Closes: #1144476
Checksums-Sha1:
 354e182ad251def9ba6fb455ab86db45e167a23d 2541 p11-kit_0.26.5-1.dsc
 6a2032f2488dfb810bacd393fd9feaf0e4a7ed00 1082584 p11-kit_0.26.5.orig.tar.xz
 ab111f33bb5a01a7feaa6e4494983778a71f261c 228 p11-kit_0.26.5.orig.tar.xz.asc
 098f8368460f8dd1c1a8e952f6a2a35829ac7e54 24628 p11-kit_0.26.5-1.debian.tar.xz
Checksums-Sha256:
 042a8c16de5351864938d98f73e0b7f179ec5f23d33800b312dd3117c015bd28 2541 p11-kit_0.26.5-1.dsc
 f2cc09111e44bf3fea58f023180b33acea90aa82d042d6fbb623fbc5ba033bb7 1082584 p11-kit_0.26.5.orig.tar.xz
 ce4e85963532772baf57dc7c63d6cc537dec2ea27a6dc49cf25028488e85c2ec 228 p11-kit_0.26.5.orig.tar.xz.asc
 a40a4ea9e417f99c1c00e3f55b232a457ad81f2eb79271fdc9c4f4dd1a925e3e 24628 p11-kit_0.26.5-1.debian.tar.xz
Files:
 1543c82b954a7c27dfe8a0743193bbbd 2541 libs optional p11-kit_0.26.5-1.dsc
 308306e889850bff08fae74ae7897a21 1082584 libs optional p11-kit_0.26.5.orig.tar.xz
 895ef8440b624e41652db746ba32092c 228 libs optional p11-kit_0.26.5.orig.tar.xz.asc
 4fa7d48a23f9b39f1c9f1a3239471f02 24628 libs optional p11-kit_0.26.5-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE0uCSA5741Jbt9PpepU8BhUOCFIQFAmqAjbAACgkQpU8BhUOC
FISZTQ//dZCYuS3hLKfgUK3kMIatuEgqwUpH5shkjhwA1oFi+Knpsz18Dp8+KTZh
OQRJCzbSTzSf74qtCEMCgiFBdndVKMUKWNr+q34/nCiH+044lTkkD6govzqk3evX
eG67hBpGP6Vu+/VZ/brls1gdJaNLKSSMuw7VzB+dxbkMyAYVxdYMR6uPAemZxR5j
cxDttc1+lvF1X83H8g0I3LKdRHNHuwb7LLZd6K5LV9JWgBOyt6dJAPVRjkNoKmRZ
5GgBdAxcZLfWrovpi090ydG34ZIeUhxQnBPio1nuWqk3o0vQwwgONVzeGSSibu26
nZ+8WvQxqUxQvaCXnL9mE9v8uPsMItpCv5jxEbsdgEfamh+r8YuMMHrW8HbZsI2+
NiWdatM5aVwbX1s9On8e0u3WXDAl4lqIqupa3DOpIKy5mQmc6vRF2+IT1vjvjUD6
Iv6whZAruT/+UItkcMn3xn2UISnKJA7d+Y4Rn8NVnk5IDEMuPAN3qYmypUKpXlsX
5mi84MdvAnCxqVVxAU0WiQmcsTMOH1bDnHZDKw+JldtMhpgtLaLn+0ridS/LMhTr
iaAHVUy0RwYIFdJQaDFcAnbRDRuRDJ/LSdeWmUhtTAujaUid28HUmeGLJlD/Hd06
mz16lvvv4zEuyhEDYVP0MFME/IYcxJG3mSrDWdeUlW9UcKHDOSk=
=3O5D
-----END PGP SIGNATURE-----