[ALSA-2026:28256] Moderate: opencryptoki security update
Type:
security
Severity:
moderate
Release date:
2026-06-26
Description:
The opencryptoki packages contain version 2.11 of the PKCS#11 API, implemented for IBM Cryptocards, such as IBM 4764 and 4765 crypto cards. These packages includes support for the IBM 4758 Cryptographic CoProcessor (with the PKCS#11 firmware loaded), the IBM eServer Cryptographic Accelerator (FC 4960 on IBM eServer System p), the IBM Crypto Express2 (FC 0863 or FC 0870 on IBM System z), and the IBM CP Assist for Cryptographic Function (FC 3863 on IBM System z). The opencryptoki packages also bring a software token implementation that can be used without any cryptographic hardware. These packages contain the Slot Daemon (pkcsslotd) and general utilities. Security Fix(es): * openCryptoki: openCryptoki: Information disclosure and Denial of Service via malformed BER-encoded cryptographic objects (CVE-2026-40253) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 opencryptoki-libs-3.26.0-2.el9_8.2.aarch64.rpm 040c2ba659b9735a32d07eaac110b904fd7a2b0d07d490837ffdcb98d24afb20
aarch64 opencryptoki-devel-3.26.0-2.el9_8.2.aarch64.rpm 2b892887a3fcffbd4f28663b56b526c2bd5269e6c614459866d5c084e58ba4cb
aarch64 opencryptoki-icsftok-3.26.0-2.el9_8.2.aarch64.rpm 9ca58ad2b23836823b9a460906c20d139cb0aedfe787503a90ca8a6ff15a77c5
aarch64 opencryptoki-swtok-3.26.0-2.el9_8.2.aarch64.rpm cb94b006fb3aaa7d16b2013d359abbe20852b242d8f977ad510b68f2d65a8cfb
aarch64 opencryptoki-3.26.0-2.el9_8.2.aarch64.rpm daf2a9f3ff43398957b12ef144a3834e13cf3f46619f20e26b92f65fc5bc794b
i686 opencryptoki-libs-3.26.0-2.el9_8.2.i686.rpm 8d41f5e08fbb7b155044e82ebc1392421394d66fb17da2bf22702af0b319a655
i686 opencryptoki-devel-3.26.0-2.el9_8.2.i686.rpm af06e3f4d89392cd03be01e448dddf3d4c947b21f5fa26bec71df87319e33dae
ppc64le opencryptoki-libs-3.26.0-2.el9_8.2.ppc64le.rpm 1e4a81660bd66288a5229c30c7b5d9f2972599cf4b0f3d9757a01c2886f837d8
ppc64le opencryptoki-3.26.0-2.el9_8.2.ppc64le.rpm 482f970c345eceb14c72feeafe5ebfaeab18045e6299a6350e7e4428123f5bcf
ppc64le opencryptoki-devel-3.26.0-2.el9_8.2.ppc64le.rpm 48baa4ba8f938ce1543605df355422180e6dcdf6371ca6bbd1835342d3f9f9b7
ppc64le opencryptoki-ccatok-3.26.0-2.el9_8.2.ppc64le.rpm 732c506824a6a945b68f3be01f28e8e1a4d96862007ca21c335ecd638cbc29e9
ppc64le opencryptoki-swtok-3.26.0-2.el9_8.2.ppc64le.rpm c849b3e18ca2baff0b4b62a69130af049162bf077e768ccdd797dae1a33f0eda
ppc64le opencryptoki-icsftok-3.26.0-2.el9_8.2.ppc64le.rpm edac00396438ff49b30ede23abd3cfff1fbc28ef6f2e756d6c86e483dc9de973
s390x opencryptoki-3.26.0-2.el9_8.2.s390x.rpm 15a906cda284804d05ac827e46265bf28e34f7cd971b7c8f32bbc83385aee49b
s390x opencryptoki-devel-3.26.0-2.el9_8.2.s390x.rpm 628fb8592155a043eae76f553af81a52f9265d861416ff9e40c732d6af4eea7a
s390x opencryptoki-libs-3.26.0-2.el9_8.2.s390x.rpm 69a90121987cc312fb4c8e460eee890992b5d79de4b90ec55a7160876902a53b
s390x opencryptoki-icsftok-3.26.0-2.el9_8.2.s390x.rpm 6ccee2caf18508c3c8186dee83824fe135c940108ebc1d6fcd2cee56da6b9ed3
s390x opencryptoki-ep11tok-3.26.0-2.el9_8.2.s390x.rpm 801b864e77c32e76dc28f0bf90dd796c2dc048fc7b077b74d7a02527a50c73cf
s390x opencryptoki-ccatok-3.26.0-2.el9_8.2.s390x.rpm 95cb4e78baa5d22d3f0d3c0ea06266559414d724b876e7a908cb3b5794249dbe
s390x opencryptoki-swtok-3.26.0-2.el9_8.2.s390x.rpm ac1ad5de85a4c25bd26dabe7f21a9178a59306f72f6be1dc6352adc75f7bb09e
s390x opencryptoki-icatok-3.26.0-2.el9_8.2.s390x.rpm e33a282d37ac945aeb70e8823ed7606f0d6181cfd0832a76dd189f2f0dce85a6
x86_64 opencryptoki-icsftok-3.26.0-2.el9_8.2.x86_64.rpm 074b2739fe0cafd087d865370caf140bd9ab79ff72d1db4b363e48e55a998c0c
x86_64 opencryptoki-swtok-3.26.0-2.el9_8.2.x86_64.rpm 19d1f966c87dafc6468fabc252c1e0bb3ffcee69451a4ff20f135cad09d41762
x86_64 opencryptoki-devel-3.26.0-2.el9_8.2.x86_64.rpm 451827c99a289a5da5beed8c99e9e5f828a1f7e779ee1a7c1d4c31741e8652a3
x86_64 opencryptoki-libs-3.26.0-2.el9_8.2.x86_64.rpm 982d777e1596230e7a6702cce34b1352d5733f9885a23824241073e29e449688
x86_64 opencryptoki-ccatok-3.26.0-2.el9_8.2.x86_64.rpm 9b06aea8567659a2bc822dd198351b6a86ba2816cc405f44f20ddcdcc0791d76
x86_64 opencryptoki-3.26.0-2.el9_8.2.x86_64.rpm e7ded1dc407bea6dc249eedf835d90395058a0963a25f29ef581e562eceaff37
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.