Impact
A local attacker, or someone with equivalent access to an RPC channel, can trigger an integer overflow in p11‑kit. By carefully crafting attribute arrays, the attacker forces the library to miscalculate memory allocations on 32‑bit systems, leading to a heap out‑of‑bounds write that can crash the RPC parsing process and cause a denial of service.
Affected Systems
Red Hat Red Hat Enterprise Linux 6 through 10, Red Hat Hardened Images, and Red Hat OpenShift Container Platform 4 are affected because they ship p11‑kit on 32‑bit architectures. Specific version numbers are not listed in the advisory, so all current releases that include p11‑kit on these platforms are considered vulnerable until a patch is released.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity for the local impact. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no widely known exploits as of this analysis. The flaw requires 32‑bit execution and local or RPC‑channel access; the attacker would need to send specially crafted messages and must have network reachability to the RPC interface. If exploited, the system may experience repeated crashes of the p11‑kit service, potentially disrupting applications that rely on PKCS#11 functionality.
OpenCVE Enrichment