openCryptoki is a PKCS#11 library and tools for Linux and AIX. In 3.25.0 and 3.26.0, there is a heap buffer overflow vulnerability in the CKM_ECDH_AES_KEY_WRAP implementation allows an attacker with local access to cause out-of-bounds writes in the host process by supplying a compressed EC public key and invoking C_WrapKey. This can lead to heap corruption, or denial-of-service.

Project Subscriptions

Vendors Products
Opencryptoki Project Subscribe
Opencryptoki Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 03 Feb 2026 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:opencryptoki_project:opencryptoki:3.25.0:*:*:*:*:*:*:*
cpe:2.3:a:opencryptoki_project:opencryptoki:3.26.0:*:*:*:*:*:*:*

Thu, 15 Jan 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 14 Jan 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Ibm
Ibm aix
Linux
Linux linux
Opencryptoki Project
Opencryptoki Project opencryptoki
Vendors & Products Ibm
Ibm aix
Linux
Linux linux
Opencryptoki Project
Opencryptoki Project opencryptoki

Tue, 13 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 13 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Description openCryptoki is a PKCS#11 library and tools for Linux and AIX. In 3.25.0 and 3.26.0, there is a heap buffer overflow vulnerability in the CKM_ECDH_AES_KEY_WRAP implementation allows an attacker with local access to cause out-of-bounds writes in the host process by supplying a compressed EC public key and invoking C_WrapKey. This can lead to heap corruption, or denial-of-service.
Title openCryptoki incorrectly calculates the buffer size in C_WrapKey with CKM_ECDH_AES_KEY_WRAP
Weaknesses CWE-131
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-01-13T19:44:53.120Z

Reserved: 2026-01-09T18:27:19.388Z

Link: CVE-2026-22791

cve-icon Vulnrichment

Updated: 2026-01-13T19:44:48.684Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-13T19:16:26.710

Modified: 2026-02-03T18:47:15.253

Link: CVE-2026-22791

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-01-13T19:06:41Z

Links: CVE-2026-22791 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-01-14T11:08:18Z

Weaknesses