Skip to content
VulniPulse
Medium6.2Red Hat Linux

Medium [CVE-2026-13757] Stack exhaustion via unbounded recursion in RPC attribute parsing

This medium-severity Red Hat Linux advisory covers CVE-2026-13757 affecting Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Discovery 2.

CVE-2026-13757 Published Jun 23, 2026Updated by vendor Jun 23, 2026
Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes.

Red Hat severity: Moderate — CVSS 6.2 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-674.

Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Discovery 2; Red Hat Hardened Images; Red Hat Insights proxy 1.5; Red Hat Update Infrastructure 5; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4.

Red Hat fixing advisory: RHSA-2026:49668, RHSA-2026:49667, RHSA-2026:54760, RHSA-2026:37469, RHSA-2026:38342, RHSA-2026:53371, RHSA-2026:54387, RHSA-2026:58981.

Affected products named by the advisory: Red Hat package: p11-kit.

Affected versions

No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.

Official advisory · high-confidence parse· fetched 15 days ago·verify at source

Fixed versions
  • p11-kit-0:0.26.4-1.el10_2
  • p11-kit-0:0.26.4-1.el9_8
  • discovery/discovery-server-rhel9:1786638573
  • discovery/discovery-ui-rhel9:1786634825
  • p11-kit-main-0.26.2-1.2.hum1
  • p11-kit-main-0.26.4-1.hum1
  • insights-proxy/insights-proxy-container-rhel9:1786433656
  • rhui5/cds-kubernetes-rhel9:1786435241
  • rhui5/cds-rhel9:1786533457
  • rhui5/haproxy-rhel9:1786533449
  • rhui5/installer-rhel9:1786435483
  • rhui5/rhua-rhel9:1786533529
  • rhui5/cds-kubernetes-tp-rhel9:1787241211
  • rhui5/installer-tp-rhel9:1787135742
  • rhui5/rhua-tp-rhel9:1787241260
  • RHSA-2026:49668
  • RHSA-2026:49667
  • RHSA-2026:54760
  • RHSA-2026:37469
  • RHSA-2026:38342
  • RHSA-2026:53371
  • RHSA-2026:54387
  • RHSA-2026:58981

Official advisory · high-confidence parse· fetched 15 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • This CVE requires same-user access to the p11-kit RPC Unix domain socket (/run/user/<uid>/p11-kit/pkcs11-*). Any process running as the socket-owning user can trigger the crash without further authentication. If p11-kit is managed via systemd --user, ensure `Restart=on-failure` is set in the unit file so that a crash is automatically recovered without manual intervention. Red Hat recommends updating p11-kit to version 0.26.3 or later, which introduces a recursion depth limit in the RPC attribute parsing and fully addresses this flaw.

Official advisory · high-confidence parse· fetched 15 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.