[ALSA-2026:5587] Moderate: opencryptoki security update
Type:
security
Severity:
moderate
Release date:
2026-03-26
Description:
The opencryptoki packages contain version 2.11 of the PKCS#11 API, implemented for IBM Cryptocards, such as IBM 4764 and 4765 crypto cards. These packages includes support for the IBM 4758 Cryptographic CoProcessor (with the PKCS#11 firmware loaded), the IBM eServer Cryptographic Accelerator (FC 4960 on IBM eServer System p), the IBM Crypto Express2 (FC 0863 or FC 0870 on IBM System z), and the IBM CP Assist for Cryptographic Function (FC 3863 on IBM System z). The opencryptoki packages also bring a software token implementation that can be used without any cryptographic hardware. These packages contain the Slot Daemon (pkcsslotd) and general utilities. Security Fix(es): * openCryptoki: openCryptoki: Privilege Escalation or Data Exposure via Symlink Following (CVE-2026-23893) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 opencryptoki-devel-3.22.0-3.el8_10.2.aarch64.rpm 105b6410e1772215b32b6ad0aa3beaf3809651eb28197ebf686c05878108effe
aarch64 opencryptoki-tpmtok-3.22.0-3.el8_10.2.aarch64.rpm 40c68358cffe15cff4a15dd0edd2bd177d1640337986f4d4db14e6efa7a4f98c
aarch64 opencryptoki-icsftok-3.22.0-3.el8_10.2.aarch64.rpm 56537e01aca7be65495f76a9d1423e430424f8a21b5d8f74c67054994c8cd2d8
aarch64 opencryptoki-swtok-3.22.0-3.el8_10.2.aarch64.rpm 9053588db958012504e64d725d8f8fa463901731a50358e097e668cc74db44c1
aarch64 opencryptoki-libs-3.22.0-3.el8_10.2.aarch64.rpm dd0a054fb074f3c4decc7e610ce16a6c44a1ff5bc6db75d03a030709cbf76d9d
aarch64 opencryptoki-3.22.0-3.el8_10.2.aarch64.rpm fecb2e3a34afa7bc7370c1e0b225ccd64a5100d3fc5e66313c60b1bdfd78a091
i686 opencryptoki-libs-3.22.0-3.el8_10.2.i686.rpm 3afdc22d15d04d5e0f17be0d98bc06fa3bef5226ebba25e9ecc6e1680024ed25
i686 opencryptoki-devel-3.22.0-3.el8_10.2.i686.rpm 3e03d127d25eeb230c20e97bfb22d0ea62cba9eed6362e1704beacecf60b613f
ppc64le opencryptoki-icsftok-3.22.0-3.el8_10.2.ppc64le.rpm 132dc320bdf83a5f6cf6974a1da38b9abb46f6388a9a14815b0fa9ab502fe5b6
ppc64le opencryptoki-swtok-3.22.0-3.el8_10.2.ppc64le.rpm 39bfece06cd4c0edf37dc98d06401f30c18c9184c768c7dc2f19f90c75601a18
ppc64le opencryptoki-tpmtok-3.22.0-3.el8_10.2.ppc64le.rpm 483292ce58de166475edbac9c9cb01dd74d3b18f1edce3b3fd93216652348063
ppc64le opencryptoki-devel-3.22.0-3.el8_10.2.ppc64le.rpm d613e842be0981f3c313307787071fad17e4da91397731dea27946f722a22a39
ppc64le opencryptoki-3.22.0-3.el8_10.2.ppc64le.rpm f7877a750c055c0acfff4ed5962a8691c6d58faa0fdb0708fdde5869905bbffe
ppc64le opencryptoki-libs-3.22.0-3.el8_10.2.ppc64le.rpm ff858f376d3c5fbba0e0cbbf821aa0baee691bce78c76cd8c2c74dbac7557de5
s390x opencryptoki-libs-3.22.0-3.el8_10.2.s390x.rpm 4a7665b3fc85e4345c298c0e2823960ae6301480ce2f23b47fd315899f0cb429
s390x opencryptoki-ep11tok-3.22.0-3.el8_10.2.s390x.rpm 6a16d7073be0d8568ec7f0751174d54173d30a4235bd16ecafd0de00adf052f5
s390x opencryptoki-ccatok-3.22.0-3.el8_10.2.s390x.rpm 854b34fc9a6d3814b5a69a0171056835c508836fa3609d24f897d1b69c3084ab
s390x opencryptoki-icsftok-3.22.0-3.el8_10.2.s390x.rpm 92e27e966382eee917a1063c0c89fff216ef4d2272a7dfb8094128657935ccbb
s390x opencryptoki-tpmtok-3.22.0-3.el8_10.2.s390x.rpm a7386e164a90163bfdcd25015117787534c788de798b314c5d80fcbb0cb5d122
s390x opencryptoki-icatok-3.22.0-3.el8_10.2.s390x.rpm ad256d69f6faefeb71b0c8c5bfef2f171721235ac66362be10bce8c464129fec
s390x opencryptoki-swtok-3.22.0-3.el8_10.2.s390x.rpm b80b670eadceb3ae4abd71d0ccd934acb6b179f877e512a64f4999d12985b727
s390x opencryptoki-3.22.0-3.el8_10.2.s390x.rpm d14bc0171fe76ac2e2af8ccfef11f6c0577c0bd178c353b28c99c61f0c2b6808
s390x opencryptoki-devel-3.22.0-3.el8_10.2.s390x.rpm d1a54c72ab5d239f3bb4df51adcf5661f68cbe367875410930fbb3fc6a8a4c87
x86_64 opencryptoki-tpmtok-3.22.0-3.el8_10.2.x86_64.rpm 0bc6446a7d879253d35cf2fc611634f6336b154583c002628d8f5da772cd3bad
x86_64 opencryptoki-icsftok-3.22.0-3.el8_10.2.x86_64.rpm 6be177a2e319ad9e2e12da46b2afc40d98759365da9a652eea008aad8a940b94
x86_64 opencryptoki-libs-3.22.0-3.el8_10.2.x86_64.rpm 8cefd531674f7a5cef7e0857c9f0ef17c0742130685f754dfcf97a8d5611fa6b
x86_64 opencryptoki-devel-3.22.0-3.el8_10.2.x86_64.rpm ce49d7bafd8033592d63c37a641d5caffe30b74f17b3ff87574f18190d70520e
x86_64 opencryptoki-3.22.0-3.el8_10.2.x86_64.rpm d3a46dfd979da0fcc45ea5e2446834eef79b02d76b55d0da33e4eacd0923342d
x86_64 opencryptoki-swtok-3.22.0-3.el8_10.2.x86_64.rpm fa60de8de3623593be4da5af8e588741201aa15870d5862f7f2a71e3e768f639
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.