{"id":"AZL-91743","summary":"CVE-2026-13757 affecting package p11-kit 0.25.0-1","details":"A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.","modified":"2026-09-03T05:27:10Z","published":"2026-06-29T19:16:40Z","upstream":["CVE-2026-13757"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-13757"}],"affected":[{"package":{"name":"p11-kit","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/p11-kit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.25.0-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91743.json"}}],"schema_version":"1.9.0"}