opencryptoki-3.26.0-2.el9_8.2

エラータID: AXSA:2026-1392:06

Release date: 
Thursday, July 30, 2026 - 21:11
Subject: 
opencryptoki-3.26.0-2.el9_8.2
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

The opencryptoki packages contain version 2.11 of the PKCS#11 API, implemented for IBM Cryptocards, such as IBM 4764 and 4765 crypto cards. These packages includes support for the IBM 4758 Cryptographic CoProcessor (with the PKCS#11 firmware loaded), the IBM eServer Cryptographic Accelerator (FC 4960 on IBM eServer System p), the IBM Crypto Express2 (FC 0863 or FC 0870 on IBM System z), and the IBM CP Assist for Cryptographic Function (FC 3863 on IBM System z). The opencryptoki packages also bring a software token implementation that can be used without any cryptographic hardware. These packages contain the Slot Daemon (pkcsslotd) and general utilities.

Security Fix(es):

* openCryptoki: openCryptoki: Information disclosure and Denial of Service via malformed BER-encoded cryptographic objects (CVE-2026-40253)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-40253
openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. In versions 3.26.0 and below, the BER/DER decoding functions in the shared common library (asn1.c) accept a raw pointer but no buffer length parameter, and trust attacker-controlled BER length fields without validating them against actual buffer boundaries. All primitive decoders are affected: ber_decode_INTEGER, ber_decode_SEQUENCE, ber_decode_OCTET_STRING, ber_decode_BIT_STRING, and ber_decode_CHOICE. Additionally, ber_decode_INTEGER can produce integer underflows when the encoded length is zero. An attacker supplying a malformed BER-encoded cryptographic object through PKCS#11 operations such as C_CreateObject or C_UnwrapKey, token loading from disk, or remote backend communication can trigger out-of-bounds reads. This affects all token backends (Soft, ICA, CCA, TPM, EP11, ICSF) since the vulnerable code is in the shared common library. A patch is available thorugh commit ed378f463ef73364c89feb0fc923f4dc867332a3.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. opencryptoki-3.26.0-2.el9_8.2.src.rpm
    MD5: cd6cdb0ca758bb96c49dbf127257d546
    SHA-256: bf746928b07b92da20373654212273eb537293973c73d092a1822b3b85700f66
    Size: 2.28 MB

Asianux Server 9 for x86_64
  1. opencryptoki-3.26.0-2.el9_8.2.x86_64.rpm
    MD5: da3d974796a7e4bc220a42c52e77c0a8
    SHA-256: 1667d5f2a923dcbe962c8abff5825bbd43f21093e33c63127bdb506f2a21a8de
    Size: 326.16 kB
  2. opencryptoki-ccatok-3.26.0-2.el9_8.2.x86_64.rpm
    MD5: 0a202fb89a9c16dbd4abe48c3b2751f1
    SHA-256: 0d1c1cbc96b9c547ecb3e59ef1683bd58f7e002d59f719dc1fd6083fc8f05c04
    Size: 368.16 kB
  3. opencryptoki-devel-3.26.0-2.el9_8.2.i686.rpm
    MD5: 9d0042f44f38f1fa6049d359ffbcf1f5
    SHA-256: 4eb5bbb51f6509011c3f418877ff195e88e8fda3c23cc4bdbf5bd98ca6956a82
    Size: 27.85 kB
  4. opencryptoki-devel-3.26.0-2.el9_8.2.x86_64.rpm
    MD5: 6c7c7b63e9531a814eeb96198e327b8b
    SHA-256: 3d62c22973bd48171a6295ddd6fe1643cac1afa6cf73816f0a40b29e7dce0b7e
    Size: 27.83 kB
  5. opencryptoki-icsftok-3.26.0-2.el9_8.2.x86_64.rpm
    MD5: 10a97b206fa3aac730dcbda6814241f7
    SHA-256: 8863d50dc756d1bf5708df7423b718f0732a8c88d43b4f7a40b44d5caf4ccc77
    Size: 150.11 kB
  6. opencryptoki-libs-3.26.0-2.el9_8.2.i686.rpm
    MD5: adb849aaec172bf375027c0a11d19b84
    SHA-256: 2ec75d99dafd57059a69e08792dff0c0d05b6bf7291959aef103c1604e332449
    Size: 85.64 kB
  7. opencryptoki-libs-3.26.0-2.el9_8.2.x86_64.rpm
    MD5: 82c1ec04dc0cdec7a3f4438050589981
    SHA-256: 7c0ace89033424724ab0f9d7d5e88ac35c6dfc94272f84a4405b22aaeef47aca
    Size: 89.94 kB
  8. opencryptoki-swtok-3.26.0-2.el9_8.2.x86_64.rpm
    MD5: b831762c0a09dc009097b12518285d20
    SHA-256: 71797a20f7eacc33bba561fc9e4519770da6593937963c5bf3e7e5a344763ce3
    Size: 277.31 kB