UbuntuUpdates.org

Package "libopencryptoki-dev"

Name: libopencryptoki-dev

Description:

PKCS#11 implementation (development)

Latest version: 3.26.0+dfsg-0ubuntu1.1
Release: resolute (26.04)
Level: security
Repository: universe
Head package: opencryptoki
Homepage: https://github.com/opencryptoki/opencryptoki

Links


Download "libopencryptoki-dev"


Other versions of "libopencryptoki-dev" in Resolute

Repository Area Version
base universe 3.26.0+dfsg-0ubuntu1
updates universe 3.26.0+dfsg-0ubuntu1.1

Changelog

Version: 3.26.0+dfsg-0ubuntu1.1 2026-09-01 16:07:42 UTC

opencryptoki (3.26.0+dfsg-0ubuntu1.1) resolute-security; urgency=medium

  * d/p/lp-2163255-fix-ckm-ecdh-aes-key-wrap-buffer-size.patch: Fix
    CKM_ECDH_AES_KEY_WRAP buffer size calculation with compressed keys,
    which could lead to an out-of-bounds write. (LP: #2163255)
    (CVE-2026-22791)
  * d/p/lp-2163253-fix-ber-der-decoder-out-of-bounds-access.patch: Fix
    possible out-of-bounds access in BER decode functions. (LP: #2163253)
    (CVE-2026-40253)
  * d/p/lp-2163254-fix-symlink-following-vulnerabilities.patch: Fix
    symlink-following vulnerabilities (CWE-59). (LP: #2163254)
    (CVE-2026-23893)

 -- Frank Heimes Tue, 18 Aug 2026 15:24:04 +0000

CVE-2026-22791 openCryptoki is a PKCS#11 library and tools for Linux and AIX. In 3.25.0 and 3.26.0, there is a heap buffer overflow vulnerability in the CKM_ECDH_AE
CVE-2026-40253 openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. In versions 3.26.0 and below, the BER/DER decoding functions in the shared
CVE-2026-23893 openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versions 2.3.2 and above are vulnerable to symlink-following when running i



About   -   Send Feedback to @ubuntu_updates