Opened 3 months ago
Closed 2 months ago
#23588 closed enhancement (fixed)
p11-kit-0.26.4
| Reported by: | Bruce Dubbs | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | elevated | Milestone: | 98-Security |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (5)
comment:1 by , 3 months ago
comment:2 by , 3 months ago
| Priority: | normal → elevated |
|---|
comment:3 by , 3 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:4 by , 3 months ago
| Milestone: | 13.1 → 98-Security |
|---|---|
| Owner: | changed from to |
| Status: | assigned → new |
0.26.4 (stable)
* Build fix [PR#773]
* Update translations [PR#743, PR#772]
0.26.3 (stable)
* server: fixed stack exhaustion via unbounded recursion in RPC attribute parsing by enforcing a recursion depth limit (CVE-2026-13757) [PR#768]
* fixed confusing error message when trying to store an existing cert with trust anchor [PR#770]
* fixed assert when parsing p11-kit files with value (") [PR#762]
* fixed numerous memory management issues [PR#751, PR#753, PR#754, PR#756, PR#758, PR#763, PR#764, PR#765, PR#766, PR#769]
* Build and test fixes [PR#746, PR#747, PR#752, PR#755, PR#757, PR#760, PR#761]
Fixed at 20bee0d351. Leaving open for SA.
comment:5 by , 2 months ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
Advisory sa-13.0-177 has been issued.
Note:
See TracTickets
for help on using tickets.

0.26.3 has fixed CVE-2026-13757. The book has 0.26.2 now.