What is CVE-2026-18938?
CVE-2026-18938 is an integer overflow vulnerability found in the p11-kit library. A local attacker, or one with access to a reachable RPC channel, can send specially crafted messages to trigger miscalculated memory allocation for nested attributes, potentially leading to memory corruption and arbitrary code execution. Affected systems should be updated to the latest version of p11-kit immediately.
Azərbaycanca: CVE-2026-18938, p11-kit kitabxanasında aşkarlanmış integer overflow zəifliyidir. Lokal hücumçu və ya RPC kanalına çıxışı olan şəxs, xüsusi hazırlanmış mesajlar göndərərək nested attribute-lar üçün yaddaş ayırmada səhv hesablamaya səbəb ola bilər. Bu, yaddaş pozulmasına və potensial olaraq ixtiyari kod icrasına yol aça bilər, ona görə də p11-kit-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-190
FAQ2
What type of flaw is CVE-2026-18938 in the p11-kit library?
It is an integer overflow vulnerability.
What can an attacker potentially achieve by exploiting CVE-2026-18938?
By sending specially crafted messages, an attacker can trigger miscalculated memory allocation for nested attributes, potentially leading to memory corruption and arbitrary code execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.