> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> USN-8707-1: openCryptoki vulnerabilities

[SOURCE] Ubuntu Security Notices [DATE: 31/08/2026 15:49] [LANGUAGE: EN]
It was discovered that primitive decoders in openCryptoki produced integer underflows when the encoded length was zero. An attacker could possibly use this issue to trigger out-of-bounds reads. (CVE-2026-40253) It was discovered that openCryptoki incorrectly handled symlinks. An attacker in the token-group could possibly use this issue to achieve privilege escalation or access sensitive information. (CVE-2026-23893) It was discovered that the CKM_ECDH_AES_KEY_WRAP implementation had a heap buffer overflow vulnerability. An attacker could possibly use this issue to trigger heap corruption, or denial-of-service. (CVE-2026-22791)
[messages.read_original_source] →