RUSTSEC-2026-0286None▾ SunlitOut-of-bounds read when decoding CKA_ALLOWED_MECHANISMS
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
cryptoki treated the CKA_ALLOWED_MECHANISMS ulValueLen byte count as a
CK_MECHANISM_TYPE element count. A valid nonempty attribute returned through
the safe Session::get_attributes API could cause construction of an
out-of-bounds slice and undefined behavior.
Possible consequences include a process crash or denial of service and potential disclosure of adjacent heap words. Upgrade to the fixed patch release for the cryptoki 0.10, 0.11, or 0.12 line.
cryptoki >= 0.12.0, < 0.12.1Upgrade to a patched release:
cryptoki 0.12.1