Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 454
Alerts This Week
Warning Icon 1 454

Fedora 43 p11-kit Critical Stack Exhaustion Fix CVE-2026-13757

fedora
Calendar Grey July 25, 2026
Scroller Fedora
Fixes stack exhaustion and memory management issues in p11-kit for Fedora 43, enhancing security and performance.
The Fedora update for p11-kit version 0.26.4 addresses stack exhaustion, error messages, and memory management issues, providing improved security and stability for PKCS#11 module ...

Summary

p11-kit provides a way to load and enumerate PKCS#11 modules, as well

as a standard configuration setup for installing PKCS#11 modules in

such a way that they're discoverable.

Update Information:

server: fixed stack exhaustion via unbounded recursion in RPC attribute parsing by enforcing a recursion depth limit (CVE-2026-13757) fixed confusing error message when trying to store an existing cert with trust anchor fixed assert when parsing p11-kit files with value (") fixed numerous memory management issues Build and test fixes Updated translations

Change Log

* Fri Jul 10 2026 Packit - 0.26.4-1 - Update to 0.26.4 upstream release

References


[ 1 ] Bug #2494560 - CVE-2026-13757 p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494560 [ 2 ] Bug #2498946 - p11-kit-0.26.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2498946

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-566791181a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: p11-kit
Product: Fedora 43
Version: 0.26.4
Release: 1.fc43
Summary: Library for loading and sharing PKCS#11 modules

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.