🛡️ openSUSE-SU-2026:20233-1 — opencryptoki (CVE-2026-22791 +1 more)
Description
Security update for openCryptoki
This update for openCryptoki fixes the following issues:
Upgrade openCryptoki to 3.26 (jsc#PED-14609)
Security fixes:
- CVE-2026-22791: supplying malformed compressed EC public key can lead to heap corruption or denial-of-service (bsc#1256673).
- CVE-2026-23893: Privilege Escalation or Data Exposure via Symlink Following (bsc#1257116).
Other fixes:
- Soft: Add support for RSA keys up to 16K bits.
- CCA: Add support for RSA keys up to 8K bits (requires CCA v8.4 or v7.6 or later).
- p11sak: Add support for generating RSA keys up to 16K bits.
- Soft/ICA: Add support for SHA512/224 and SHA512/256 key derivation mechanism (CKM_SHA512_224_KEY_DERIVATION and CKM_SHA512_256_KEY_DERIVATION).
- Soft/ICA/CCA/EP11: Add support for SHA-HMAC key types CKK_SHAxxx_HMAC and key gen mechanisms CKM_SHAxxx_KEY_GEN.
- p11sak: Add support for SHA-HMAC key types and key generation.
- p11sak: Add support for key wrap and unwrap commands to export and import private and secret keys by means of key wrapping/unwrapping
with various key wrapping mechanism.
- p11kmip: Add support for using an HSM-protected TLS client key via a PKCS#11 provider.
- p11sak: Add support for exporting non-sensitive private keys to password protected PEM files.
- Add support for canceling an operation via NULL mechanism pointer at C_XxxInit() call as an alternative to C_SessionCancel() (PKCS#11 v3.0).
- EP11: Add support for pairing friendly BLS12-381 EC curve for sign/verify using CKM_IBM_ECDSA_OTHER and signature/public key aggregation using CKM_IBM_EC_AGGREGATE.
- p11sak: Add support for generating BLS12-381 EC keys.
- EP11: Add support for IBM-specific ML-DSA and ML-KEM key types and mechanisms (requires an EP11 host library v4.2 or later, and
a CEX8P crypto card with firmware v9.6 or later on IBM z17, and v8.39 or later on IBM z16).
- CCA: Add support for IBM-specific ML-DSA and ML-KEM key types and mechanisms (requires CCA v8.4 or later).
- Soft: Add support for IBM-specific ML-DSA and ML-KEM key types and mechanisms (requires OpenSSL 3.5 or later, or the OQS-provider must be configured).
- p11sak: Add support for IBM-specific ML-DSA and ML-KEM key types.
- Bug fixes.
Affected software
openSUSE-SU-2026:20233-1 is recorded against 1 package.
- opencryptoki (fixed in 3.26.0-160000.1.1)
Timeline and source
Published on 13 February 2026 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| opencryptoki | — | 3.26.0-160000.1.1 |
References
Similar Threats
- Unknown ALSA-2026:28256
- Unknown ALSA-2026:26352
- Medium CVE-2026-40253
- Unknown CLSA-2026-1775212043
- Unknown CLSA-2026-1774952276
Free Vulnerability Check
Is your site affected by openSUSE-SU-2026:20233-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against openSUSE-SU-2026:20233-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.