Latest: CVE-2026-22791 - openCryptoki incorrectly calculates the buffer size in C_WrapKey with CKM_ECDH_A...

Latest: CVE-2026-22791 - openCryptoki incorrectly calculates the buffer size in C_WrapKey with CKM_ECDH_A...

CVE ID : CVE-2026-22791 Published : Jan. 13, 2026, 7:06 p.m. | 14 minutes ago Description : openCryptoki is a PKCS#11 library and tools for Linux and AIX. In 3.25.0 and 3.26.0, there is a heap buffer overflow vulnerability in the CKM_ECDH_AES_KEY_WRAP implementation allows an attacker with local access to cause out-of-bounds writes in the host process by supplying a compressed EC public key and invoking C_WrapKey. This can lead to heap corruption, or denial-of-service. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Published
Jan. 13, 2026
Affected Product: Linux
Attack Vector: local

Source: Telegram CVE Monitor