Updated p11-kit packages fix security vulnerabilities
Publication date: 28 Sep 2026Modification date: 28 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-13757 , CVE-2026-18938
Description
The updated packages fix security vulnerabilities:
Stack exhaustion via unbounded recursion in rpc attribute parsing.
(CVE-2026-13757)
Integer overflow in rpc attribute-array length calculation can
under-allocate nested attribute storage on 32 bit systems.
(CVE-2026-18938)
References
- https://bugs.mageia.org/show_bug.cgi?id=35906
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q6TQ5QWOGE7ZBPZGVINQXHGKAYSV4IMF/
- https://bugzilla.redhat.com/show_bug.cgi?id=2494556
- https://github.com/p11-glue/p11-kit/issues/767
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AD5OWYEURQQ756QI27UWHAMDLD5B6WGZ/
- https://www.cve.org/CVERecord?id=CVE-2026-13757
- https://www.cve.org/CVERecord?id=CVE-2026-18938
SRPMS
10/core
- p11-kit-0.25.10-1.1.mga10