Logo
componentp11-kit
Name
p11-kit
Version
0.26.2
Type
library
Description
Provides a way to load and enumerate PKCS#11 modules
Licenses
BSD-3-Clause
PURL
-
CPE
cpe:2.3:*:p11-kit_project:p11-kit:0.26.2:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
kirkstone
0.24.1
scarthgap
0.25.3

Vulnerabilities#


Name
Analysis
Description
Not Affected
A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.