Medium [CVE-2026-13757] Stack exhaustion via unbounded recursion in RPC attribute parsing
This medium-severity Red Hat Linux advisory covers CVE-2026-13757 affecting Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Discovery 2.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes.
Red Hat severity: Moderate — CVSS 6.2 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-674.
Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Discovery 2; Red Hat Hardened Images; Red Hat Insights proxy 1.5; Red Hat Update Infrastructure 5; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4.
Red Hat fixing advisory: RHSA-2026:49668, RHSA-2026:49667, RHSA-2026:54760, RHSA-2026:37469, RHSA-2026:38342, RHSA-2026:53371, RHSA-2026:54387, RHSA-2026:58981.
Affected products named by the advisory: Red Hat package: p11-kit.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 15 days ago·verify at source
- p11-kit-0:0.26.4-1.el10_2
- p11-kit-0:0.26.4-1.el9_8
- discovery/discovery-server-rhel9:1786638573
- discovery/discovery-ui-rhel9:1786634825
- p11-kit-main-0.26.2-1.2.hum1
- p11-kit-main-0.26.4-1.hum1
- insights-proxy/insights-proxy-container-rhel9:1786433656
- rhui5/cds-kubernetes-rhel9:1786435241
- rhui5/cds-rhel9:1786533457
- rhui5/haproxy-rhel9:1786533449
- rhui5/installer-rhel9:1786435483
- rhui5/rhua-rhel9:1786533529
- rhui5/cds-kubernetes-tp-rhel9:1787241211
- rhui5/installer-tp-rhel9:1787135742
- rhui5/rhua-tp-rhel9:1787241260
- RHSA-2026:49668
- RHSA-2026:49667
- RHSA-2026:54760
- RHSA-2026:37469
- RHSA-2026:38342
- RHSA-2026:53371
- RHSA-2026:54387
- RHSA-2026:58981
Official advisory · high-confidence parse· fetched 15 days ago·verify at source
Mitigation checklist
- This CVE requires same-user access to the p11-kit RPC Unix domain socket (/run/user/<uid>/p11-kit/pkcs11-*). Any process running as the socket-owning user can trigger the crash without further authentication. If p11-kit is managed via systemd --user, ensure `Restart=on-failure` is set in the unit file so that a crash is automatically recovered without manual intervention. Red Hat recommends updating p11-kit to version 0.26.3 or later, which introduces a recursion depth limit in the RPC attribute parsing and fully addresses this flaw.
Official advisory · high-confidence parse· fetched 15 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.