CVE-2026-2100
Rocky Linux vulnerability analysis and mitigation

Overview

CVE-2026-2100 is a NULL dereference / access of uninitialized pointer vulnerability in p11-kit, a library for managing PKCS#11 modules. A remote attacker can exploit this flaw by calling the C_DeriveKey function on a remote token with IBM kyber or IBM btc derive mechanism parameters set to NULL, causing the RPC client to attempt to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. Affected software includes p11-kit (confirmed in version 0.26.1 and earlier), Red Hat Enterprise Linux 9.0 and 10.0, and Red Hat Hardened Images. The vulnerability was first reported on February 6, 2026, and patched upstream on January 27, 2026 (merged before public disclosure). It carries a CVSS v3.1 base score of 7.5 (High) per NVD (Red Hat CVE, Red Hat Bugzilla).

Technical details

The root cause is an access of uninitialized pointer (CWE-824) in the p11_rpc_buffer_get_ibm_kyber_mech_param_update and p11_rpc_buffer_get_ibm_btc_derive_mech_param_update functions within rpc-message.c. Specifically, the local variable data is declared without initialization; when certain mechanism parameters (e.g., pCipher or pChainCode) are NULL, the code path that would populate data is skipped, but data is subsequently passed to memcpy or assigned directly — constituting use of an uninitialized value. The flaw was discovered via static analysis and requires no authentication or user interaction to trigger, as it is reachable over the network through the PKCS#11 RPC interface (Red Hat Bugzilla, p11-kit PR #740).

Impact

Successful exploitation can cause an application-level denial of service or unpredictable system states in any process using p11-kit's remote token functionality. Because the vulnerability is network-accessible with no authentication required and low attack complexity, it poses a broad availability risk to systems running p11-kit as part of cryptographic infrastructure (e.g., smart card or HSM integrations). There is no confidentiality or integrity impact identified; the primary consequence is service disruption or crash of the affected application (Red Hat CVE, Feedly).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of this report (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.095%, indicating a low probability of exploitation in the near term. No threat actor attribution has been reported.

Mitigation and workarounds

The upstream fix was merged into p11-kit master on January 27, 2026 (PR #740), and released as p11-kit version 0.26.2 (p11-kit PR #740). Red Hat issued security advisories addressing this issue for RHEL 10 (RHSA-2026:18143, package p11-kit-0.26.2-1.el10) and RHEL 9 (RHSA-2026:18599), both published May 19, 2026 (RHSA-2026:18143, Red Hat Bugzilla). Additional advisories were issued for Red Hat Hardened Images (RHSA-2026:7065, RHSA-2026:21275, RHSA-2026:22634). As a workaround where patching is not immediately possible, apply network segmentation to restrict access to p11-kit RPC services from untrusted network sources.

Community reactions

Red Hat rated this vulnerability as Moderate severity and issued multiple errata across RHEL 9, RHEL 10, and Hardened Images (RHSA-2026:18143). The issue was also picked up by downstream distributions including Fedora, openSUSE, Slackware, and NixOS, which issued their own updates. Coverage appeared in Linux security news outlets such as pro-linux.de and linuxsecurity.com, and the Yocto Project security mailing list flagged the issue for embedded Linux users.

Additional resources


SourceThis report was generated using AI

Related Rocky Linux vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-70906HIGH7.5
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1.7.0-openjdk-demo
NoYesAug 18, 2026
CVE-2026-61308MEDIUM6.8
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-17-openjdk-fastdebug
NoYesAug 18, 2026
CVE-2026-73434MEDIUM6.1
  • NixOS logoNixOS
  • gstreamer1-plugins-good-gtk
NoYesAug 12, 2026
CVE-2026-70907MEDIUM5.3
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1.8.0-openjdk.src
NoYesAug 18, 2026
CVE-2026-60589LOW3.7
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-25-openjdk-src
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management