{"id":"CVE-2026-22791","summary":"openCryptoki incorrectly calculates the buffer size in C_WrapKey with CKM_ECDH_AES_KEY_WRAP","details":"openCryptoki is a PKCS#11 library and tools for Linux and AIX. In 3.25.0 and 3.26.0, there is a heap buffer overflow vulnerability in the CKM_ECDH_AES_KEY_WRAP implementation allows an attacker with local access to cause out-of-bounds writes in the host process by supplying a compressed EC public key and invoking C_WrapKey. This can lead to heap corruption, or denial-of-service.","aliases":["GHSA-26f5-3mwq-4wm7"],"modified":"2026-04-12T20:23:11.469987Z","published":"2026-01-13T19:06:41.052Z","related":["SUSE-SU-2026:0291-1","SUSE-SU-2026:20345-1","SUSE-SU-2026:20434-1","openSUSE-SU-2026:10048-1","openSUSE-SU-2026:20233-1"],"database_specific":{"cna_assigner":"GitHub_M","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22791.json","cwe_ids":["CWE-131"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22791.json"},{"type":"ADVISORY","url":"https://github.com/opencryptoki/opencryptoki/security/advisories/GHSA-26f5-3mwq-4wm7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22791"},{"type":"FIX","url":"https://github.com/opencryptoki/opencryptoki/commit/785d7577e1477d12fbe235554e7e7b24f2de34b7"},{"type":"FIX","url":"https://github.com/opencryptoki/opencryptoki/commit/e37e9127deeeb7bf3c3c4d852c594256c57ec3a8"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/opencryptoki/opencryptoki","events":[{"introduced":"c20ccf12bab4877088a2b8b01a3168bfe407218b"},{"fixed":"e37e9127deeeb7bf3c3c4d852c594256c57ec3a8"}]}],"versions":["v3.25.0","v3.26.0"],"database_specific":{"vanir_signatures":[{"signature_type":"Line","signature_version":"v1","id":"CVE-2026-22791-ab0097b5","target":{"file":"usr/lib/common/mech_ec.c"},"deprecated":false,"digest":{"line_hashes":["226477995178739894609747281148978231141","90582510409175925441890423162824805649","312040314689345286489358660949362564935","4963154249892905667818814212711724135","319784867578471114566398209225041860996","11850901699426370992076550726845382058","245630710661004154871949829406654311185","198549139072610798345178231600191831625","304918089966536043204796381273153575593","271663136754466977308943617290000196341","51180500979305882467950678184769479303","272901249383304781112554343596231118946","265942702912718186905788058304296951797","254595667723479315873100659991366688541","149186101120539004144257338613389492735","256307837297491195850591919973796748588","133597811745810610737371631617388622530","227545471864423048252211748479531583904","44717050646128655830850863379594588733","9063586468038997097252819990760266172","54710517467226751563252007790750601476","336588038692614644934088607933890017794","109968421720439245208155981641120722605","288016549328721859344315098306975709880","156443257410496777152554369453495840434","218472382166509017487003521631771790146","41881049883270416230384799389929366288","131093696008111627277357666258541434633","79813566258645363386565427794014645458","285289959971436275543783131575115783731","73008816575143904149649613864506990944","121328953299251612404915873139531678200","140983407937943147380031504335962912042","54611718602689574943986319481941841729","149482236436839880211814980980821143698","308419704755883732229334929897371358659"],"threshold":0.9},"source":"https://github.com/opencryptoki/opencryptoki/commit/e37e9127deeeb7bf3c3c4d852c594256c57ec3a8"},{"signature_type":"Function","signature_version":"v1","id":"CVE-2026-22791-e058ce81","target":{"file":"usr/lib/common/mech_ec.c","function":"ecdh_aes_key_wrap"},"deprecated":false,"digest":{"function_hash":"260597570153548620921498641410558710071","length":6212},"source":"https://github.com/opencryptoki/opencryptoki/commit/e37e9127deeeb7bf3c3c4d852c594256c57ec3a8"}],"vanir_signatures_modified":"2026-04-12T20:23:11Z","source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22791.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H"}]}