Skip to content
Red HatCVE-2026-18938

Red Hat p11-kit. A local attacker: integer overflow

Medium6.2CVE-2026-18938 · Published Aug 7, 2026 · updated Aug 14, 2026

A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to miscalculate memory allocation for nested attributes. This leads to a memory corruption issue, specifically a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, resulting in a Denial of Service (DoS). This vulnerability is only exploitable on 32 bit systems.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Red Hat Hardened Images
Product
all versionsNo fix yet
Red Hat OpenShift Container Platform 4
Product
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-122

More Red Hat advisories

All Red Hat
Advisory
Red Hat libvirt: user could define virtual networks to inject arbitrary
Low2.3Aug 7
Red Hat dracut: command injection
High7.5Aug 7
Red Hat fixfiles script: race condition
Medium4.4Aug 7
Red Hat udisks2: privilege escalation
High7.8Aug 6
Red Hat GStreamer gst-plugins-good: denial of service
High7.5Aug 6
Red Hat SAML broker: capture-replay
Medium6.4Aug 6

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.