Incorrect Calculation of Buffer Size in Opencryptoki - CVE-2026-22791
Published: January 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to a boundary error within the CKM_ECDH_AES_KEY_WRAP implementation in ecdh_aes_key_wrap() function in usr/lib/common/mech_ec.c. A remote attacker can pass a specially crafted public EC key to the application and perform a denial of service attack.
Affected software
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Server Applications Module
openEuler
Ubuntu
opencryptoki (Ubuntu package)
opencryptoki
opencryptoki-help
opencryptoki-devel
opencryptoki-debugsource
opencryptoki-debuginfo
openCryptoki-devel
openCryptoki-debuginfo
openCryptoki-debugsource
openCryptoki-64bit-debuginfo
openCryptoki
openCryptoki-64bit
How to mitigate CVE-2026-22791
opencryptoki - update to 3.26.0-1
opencryptoki-help - update to 3.26.0-1
opencryptoki-devel - update to 3.26.0-1
opencryptoki-debugsource - update to 3.26.0-1
opencryptoki-debuginfo - update to 3.26.0-1
openCryptoki-devel - update to 3.26.0-150700.5.9.1
openCryptoki-debuginfo - update to 3.26.0-150700.5.9.1
openCryptoki-debugsource - update to 3.26.0-150700.5.9.1
openCryptoki-64bit-debuginfo - update to 3.26.0-150700.5.9.1
openCryptoki - update to 3.26.0-150700.5.9.1
openCryptoki-64bit - update to 3.26.0-150700.5.9.1
External References
Related Security Bulletins
- Buffer overflow in Opencryptoki
- SUSE update for openCryptoki
- openEuler 24.03 LTS SP3 update for opencryptoki
- openEuler 24.03 LTS SP1 update for opencryptoki
- openEuler 24.03 LTS SP2 update for opencryptoki
- openEuler 24.03 LTS update for opencryptoki
- openEuler 22.03 LTS SP4 update for opencryptoki
- Ubuntu update for opencryptoki