UBUNTU-CVE-2026-22791

Source
https://ubuntu.com/security/CVE-2026-22791
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-22791.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-22791
Upstream
Downstream
Related
Published
2026-01-13T19:16:00Z
Modified
2026-09-01T21:00:11Z
Severity
  • 6.6 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H CVSS Calculator
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

openCryptoki is a PKCS#11 library and tools for Linux and AIX. In 3.25.0 and 3.26.0, there is a heap buffer overflow vulnerability in the CKM_ECDH_AES_KEY_WRAP implementation allows an attacker with local access to cause out-of-bounds writes in the host process by supplying a compressed EC public key and invoking C_WrapKey. This can lead to heap corruption, or denial-of-service.

References

Affected packages

Ubuntu:25.10 / opencryptoki

Package

Name
opencryptoki
Purl
pkg:deb/ubuntu/opencryptoki?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.24.0+git20250128.0462717+dfsg-0ubuntu1
3.25.0+dfsg-0ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libopencryptoki0",
            "binary_version": "3.25.0+dfsg-0ubuntu1"
        },
        {
            "binary_name": "opencryptoki",
            "binary_version": "3.25.0+dfsg-0ubuntu1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-22791.json"

Ubuntu:26.04:LTS / opencryptoki

Package

Name
opencryptoki
Purl
pkg:deb/ubuntu/opencryptoki?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.26.0+dfsg-0ubuntu1.1

Affected versions

3.*
3.25.0+dfsg-0ubuntu1
3.26.0+dfsg-0ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libopencryptoki0",
            "binary_version": "3.26.0+dfsg-0ubuntu1.1"
        },
        {
            "binary_name": "opencryptoki",
            "binary_version": "3.26.0+dfsg-0ubuntu1.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-22791.json"