🛡️ openSUSE-SU-2026:20233-1 — opencryptoki (CVE-2026-22791 +1 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for openCryptoki

This update for openCryptoki fixes the following issues:

Upgrade openCryptoki to 3.26 (jsc#PED-14609)

Security fixes:

  • CVE-2026-22791: supplying malformed compressed EC public key can lead to heap corruption or denial-of-service (bsc#1256673).
  • CVE-2026-23893: Privilege Escalation or Data Exposure via Symlink Following (bsc#1257116).

Other fixes:

  • Soft: Add support for RSA keys up to 16K bits.
  • CCA: Add support for RSA keys up to 8K bits (requires CCA v8.4 or v7.6 or later).
  • p11sak: Add support for generating RSA keys up to 16K bits.
  • Soft/ICA: Add support for SHA512/224 and SHA512/256 key derivation mechanism (CKM_SHA512_224_KEY_DERIVATION and CKM_SHA512_256_KEY_DERIVATION).
  • Soft/ICA/CCA/EP11: Add support for SHA-HMAC key types CKK_SHAxxx_HMAC and key gen mechanisms CKM_SHAxxx_KEY_GEN.
  • p11sak: Add support for SHA-HMAC key types and key generation.
  • p11sak: Add support for key wrap and unwrap commands to export and import private and secret keys by means of key wrapping/unwrapping

with various key wrapping mechanism.

  • p11kmip: Add support for using an HSM-protected TLS client key via a PKCS#11 provider.
  • p11sak: Add support for exporting non-sensitive private keys to password protected PEM files.
  • Add support for canceling an operation via NULL mechanism pointer at C_XxxInit() call as an alternative to C_SessionCancel() (PKCS#11 v3.0).
  • EP11: Add support for pairing friendly BLS12-381 EC curve for sign/verify using CKM_IBM_ECDSA_OTHER and signature/public key aggregation using CKM_IBM_EC_AGGREGATE.
  • p11sak: Add support for generating BLS12-381 EC keys.
  • EP11: Add support for IBM-specific ML-DSA and ML-KEM key types and mechanisms (requires an EP11 host library v4.2 or later, and

a CEX8P crypto card with firmware v9.6 or later on IBM z17, and v8.39 or later on IBM z16).

  • CCA: Add support for IBM-specific ML-DSA and ML-KEM key types and mechanisms (requires CCA v8.4 or later).
  • Soft: Add support for IBM-specific ML-DSA and ML-KEM key types and mechanisms (requires OpenSSL 3.5 or later, or the OQS-provider must be configured).
  • p11sak: Add support for IBM-specific ML-DSA and ML-KEM key types.
  • Bug fixes.

Affected software

openSUSE-SU-2026:20233-1 is recorded against 1 package.

  • opencryptoki (fixed in 3.26.0-160000.1.1)

Timeline and source

Published on 13 February 2026 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-02-13
Updated 2026-08-20
Modified 2026-03-23
Fix URL N/A

Affected Packages

Software From version Fixed in
opencryptoki 3.26.0-160000.1.1

Similar Threats

Free Vulnerability Check

Is your site affected by openSUSE-SU-2026:20233-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against openSUSE-SU-2026:20233-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2026