[ALSA-2026:26352] Moderate: opencryptoki security update
Type:
security
Severity:
moderate
Release date:
2026-06-17
Description:
The opencryptoki packages contain version 2.11 of the PKCS#11 API, implemented for IBM Cryptocards, such as IBM 4764 and 4765 crypto cards. These packages includes support for the IBM 4758 Cryptographic CoProcessor (with the PKCS#11 firmware loaded), the IBM eServer Cryptographic Accelerator (FC 4960 on IBM eServer System p), the IBM Crypto Express2 (FC 0863 or FC 0870 on IBM System z), and the IBM CP Assist for Cryptographic Function (FC 3863 on IBM System z). The opencryptoki packages also bring a software token implementation that can be used without any cryptographic hardware. These packages contain the Slot Daemon (pkcsslotd) and general utilities. Security Fix(es): * openCryptoki: openCryptoki: Information disclosure and Denial of Service via malformed BER-encoded cryptographic objects (CVE-2026-40253) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 opencryptoki-libs-3.22.0-3.el8_10.3.aarch64.rpm 0afbdbb5321713f2429cf37ee82aa5ef0470b0699b2769b2e3c031c616b2a44a
aarch64 opencryptoki-tpmtok-3.22.0-3.el8_10.3.aarch64.rpm 0e0aef8016b73ce7be7969210cc4f0124cbe35b3a13585d51a1f71f183899eee
aarch64 opencryptoki-devel-3.22.0-3.el8_10.3.aarch64.rpm 533a3540167f9928e9e52c812a56c8ae82bde047e974ed5ac79da14bc4ec223d
aarch64 opencryptoki-3.22.0-3.el8_10.3.aarch64.rpm 646effa507108293c66257fa36f188211975ebbc65007c66d2c8cd04865bb540
aarch64 opencryptoki-icsftok-3.22.0-3.el8_10.3.aarch64.rpm 742c683636be8ec4ad566cc6c0da0be23c25f4aab38d01d96977538ffc7b3339
aarch64 opencryptoki-swtok-3.22.0-3.el8_10.3.aarch64.rpm a9f1d79186724e315acbca8e06da980a618a1954783b270af103e036ffb40985
i686 opencryptoki-libs-3.22.0-3.el8_10.3.i686.rpm 51bbbe30cbaa4a48a70f58e9d8581269c651ae354c6d2489daf17564cb4401d6
i686 opencryptoki-devel-3.22.0-3.el8_10.3.i686.rpm b72bc9c5a1065edb9929bfe3175f30e7f97808311ad27e9209c09c1700b178ff
ppc64le opencryptoki-devel-3.22.0-3.el8_10.3.ppc64le.rpm 27207d34e8a5cffcf42d76c41e97b90602146d98818b5e9f5c6a72c5e8e79d46
ppc64le opencryptoki-tpmtok-3.22.0-3.el8_10.3.ppc64le.rpm 29a873c2f43e5169c043c0dc15f54b088e9a2dc55feea37d9a64fc368cd541ac
ppc64le opencryptoki-icsftok-3.22.0-3.el8_10.3.ppc64le.rpm 37973a086ac6ff3ee3d413287972d54e90aa20bc3cb6cb78a2c80c3a56643fcd
ppc64le opencryptoki-3.22.0-3.el8_10.3.ppc64le.rpm 86ef635116354aecd05dab6511c5a13f6677a08a52699b19b394245e1311645d
ppc64le opencryptoki-swtok-3.22.0-3.el8_10.3.ppc64le.rpm 8da3a52bef734259f197219a702eecd79562e32403de2f39aa609579e33abb4d
ppc64le opencryptoki-libs-3.22.0-3.el8_10.3.ppc64le.rpm 97301d14e9383250bbc4b65fc3ff434e28bf7bac7d7e585fc4e4bb0cde5445d5
s390x opencryptoki-ccatok-3.22.0-3.el8_10.3.s390x.rpm 1c5c2388f14f8c1b475c58304f9b99f3aa6f10535b885a0b6646b1afc2fa51bb
s390x opencryptoki-icsftok-3.22.0-3.el8_10.3.s390x.rpm 40476e1dc2ea0fc91341e81b740de43c51f2f505b3008956333f9c4baf68dace
s390x opencryptoki-3.22.0-3.el8_10.3.s390x.rpm 6eff9fa6ebe0a2791487cd599eeb6707dc50b8f2210e2679bb9c99760cbc162a
s390x opencryptoki-ep11tok-3.22.0-3.el8_10.3.s390x.rpm 78575308b36cf91aafff10550c4116ce5164be7580e58b07100360961ae4935a
s390x opencryptoki-icatok-3.22.0-3.el8_10.3.s390x.rpm 8845fc4ecc609dfc79c550ffcb7e124e97604f859963e199ce3f38bde842bde2
s390x opencryptoki-swtok-3.22.0-3.el8_10.3.s390x.rpm 8d8a4c6972d477232e6a0cb57c5497e4d5b3a0f1016a43967e88ce7983dab2e6
s390x opencryptoki-libs-3.22.0-3.el8_10.3.s390x.rpm 938ec2931853915b193bf571a88c645beab9ce9cfb313fc437e94cea4440856a
s390x opencryptoki-devel-3.22.0-3.el8_10.3.s390x.rpm bb3f3010b566b517e8d403af31c020c635e6196d52430ef43e0af482b5a02158
s390x opencryptoki-tpmtok-3.22.0-3.el8_10.3.s390x.rpm f18a8a15b5e57ecc8bd4719a82b4332f239850280fe5f4f239d2ac39d4731cb2
x86_64 opencryptoki-swtok-3.22.0-3.el8_10.3.x86_64.rpm 0c5232a225791804500584190f5659f953b3449b73c2bcf0f86da1de85585b94
x86_64 opencryptoki-icsftok-3.22.0-3.el8_10.3.x86_64.rpm 1477fe144a458d7aff6ca784e2ba53c542044de0e19ddff689fdd384c97d8b47
x86_64 opencryptoki-tpmtok-3.22.0-3.el8_10.3.x86_64.rpm 5f90c13c1192dce57e11828f5af88beb8458a4c5eee7d0203bdca14629baf3c9
x86_64 opencryptoki-3.22.0-3.el8_10.3.x86_64.rpm 7a41de9b08a2157fb0753fc57c8f61d438904a5cf9e1a98bab860123c1735926
x86_64 opencryptoki-devel-3.22.0-3.el8_10.3.x86_64.rpm c28d274b9b55857b487f0d2a5477fd24f0f26a74ef6b2f3907916f66c51e9855
x86_64 opencryptoki-libs-3.22.0-3.el8_10.3.x86_64.rpm ecf47516cfcae906a6d0243feb7d20c4841563d5a2799a8fef39762b5434f1de
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.