Impact
A heap-based buffer over-read has been discovered in the RPC protocol used by thep11-kit server/remote commands and the client library. When the remote entity supplies a byte array through a serialized PKCS#11 function call, the receiving entity may allow the reading of up to 4 bytes of memory past the heap allocation.
Patches
The upstream 0.23.22 release should fix the issue.
Workarounds
None.
References
None.
For more information
If you have any questions or comments about this advisory:
If the questions should be treated confidential, follow our security policy to reach out to us.
Impact
A heap-based buffer over-read has been discovered in the RPC protocol used by thep11-kit server/remote commands and the client library. When the remote entity supplies a byte array through a serialized PKCS#11 function call, the receiving entity may allow the reading of up to 4 bytes of memory past the heap allocation.
Patches
The upstream 0.23.22 release should fix the issue.
Workarounds
None.
References
None.
For more information
If you have any questions or comments about this advisory:
If the questions should be treated confidential, follow our security policy to reach out to us.