[ALSA-2026:5603] Moderate: opencryptoki security update
Type:
security
Severity:
moderate
Release date:
2026-03-26
Description:
The opencryptoki packages contain version 2.11 of the PKCS#11 API, implemented for IBM Cryptocards, such as IBM 4764 and 4765 crypto cards. These packages includes support for the IBM 4758 Cryptographic CoProcessor (with the PKCS#11 firmware loaded), the IBM eServer Cryptographic Accelerator (FC 4960 on IBM eServer System p), the IBM Crypto Express2 (FC 0863 or FC 0870 on IBM System z), and the IBM CP Assist for Cryptographic Function (FC 3863 on IBM System z). The opencryptoki packages also bring a software token implementation that can be used without any cryptographic hardware. These packages contain the Slot Daemon (pkcsslotd) and general utilities. Security Fix(es): * openCryptoki: openCryptoki: Privilege Escalation or Data Exposure via Symlink Following (CVE-2026-23893) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 opencryptoki-icsftok-3.25.0-4.el9_7.2.aarch64.rpm 0436ac7f890738cfef6aca63b066e30361e9f512cf3221e4da1469a1961a5b93
aarch64 opencryptoki-libs-3.25.0-4.el9_7.2.aarch64.rpm be2b30fd9000a504b206b52ba2e1dc583079bca6439cbdb76bb10030ae202620
aarch64 opencryptoki-swtok-3.25.0-4.el9_7.2.aarch64.rpm dda05498ecebb184d2d76e4cfe9398087121a52f265558ef8b4d67f785be803b
aarch64 opencryptoki-3.25.0-4.el9_7.2.aarch64.rpm e3a51132325f5376131ac593335e7d78c595b7de01e15173db057821d2c79162
aarch64 opencryptoki-devel-3.25.0-4.el9_7.2.aarch64.rpm f176574c03281a298d2ff15849b76f0f70af2f2a5ef863912ebfcd67774e68c6
i686 opencryptoki-libs-3.25.0-4.el9_7.2.i686.rpm 04c1154b8ac184d9524de765b067089d068857dd3c05a32b6d8b0d2a1709d9a3
i686 opencryptoki-devel-3.25.0-4.el9_7.2.i686.rpm ce9d87928964b7aaf484f08e6f6b2f08ff5d0723786f9cb3c5efbf85cc927a79
ppc64le opencryptoki-ccatok-3.25.0-4.el9_7.2.ppc64le.rpm 326b6ff0b26d9133b05bdc8a7e24a7cd3748f07298962bbe135ed22f8aaff2c7
ppc64le opencryptoki-devel-3.25.0-4.el9_7.2.ppc64le.rpm 7a2827c2e16e4825ec472701f0bc07962042085dea2ef2fa8d8f626c5a52a28e
ppc64le opencryptoki-libs-3.25.0-4.el9_7.2.ppc64le.rpm 81b20f10068174343f0c4dec5e30db3a3b206939eed11f035522829c2fc44c43
ppc64le opencryptoki-3.25.0-4.el9_7.2.ppc64le.rpm 89e8350c22251c00ccd890daf57ef88d3f6e8fa790c2b51dc58b5e2857bcc938
ppc64le opencryptoki-swtok-3.25.0-4.el9_7.2.ppc64le.rpm 8f6ebca2db3ed868a39df468ff9bf358504d87412a5d1fa34969af8d12404df0
ppc64le opencryptoki-icsftok-3.25.0-4.el9_7.2.ppc64le.rpm d8fa2b31ffd9f3273e92c6fa5cdd3b40a2dd3f87033f7dbef6d97f5969736773
s390x opencryptoki-3.25.0-4.el9_7.2.s390x.rpm 00704252c9cde8f8046d111551f2a033848a0b878889cbd3d0797658f20f593f
s390x opencryptoki-icsftok-3.25.0-4.el9_7.2.s390x.rpm 20e25e8bfd5ae5a9d85576fbdd1e181ac299532188430a175ad27eb814d34206
s390x opencryptoki-ccatok-3.25.0-4.el9_7.2.s390x.rpm 61602eb8d7a238c9b8d6110bbe21609e78e13fe57ba6a3ba99741fa00de0cb25
s390x opencryptoki-devel-3.25.0-4.el9_7.2.s390x.rpm 7a4420af7a3a89f2c9c6c194794220f112bc75cc32baee585d4e0dd17acce936
s390x opencryptoki-libs-3.25.0-4.el9_7.2.s390x.rpm b6c2905e708d0975f79546c530c85f03e75bd21cced261fb9816d8ea5d5f5412
s390x opencryptoki-icatok-3.25.0-4.el9_7.2.s390x.rpm bd33d1b28e61409a1f28ebfe22ced551d7ffe1a852981dc98d04d6852bb4cec4
s390x opencryptoki-swtok-3.25.0-4.el9_7.2.s390x.rpm c01d2f083629d5669574547ff2883b85706eee77bb449e0a2f849bee277f3c97
s390x opencryptoki-ep11tok-3.25.0-4.el9_7.2.s390x.rpm e15b3dc5b2090dbd7ce3e356151ca404643afc8f0c57b1bf40d7583999255d30
x86_64 opencryptoki-icsftok-3.25.0-4.el9_7.2.x86_64.rpm 0e51aef646aa823ba6a749ff8c057edabab7761dabc263e7e045f4eab317cd52
x86_64 opencryptoki-swtok-3.25.0-4.el9_7.2.x86_64.rpm 1b237d0082860558b6028c53b0bff9836501956795bb0694ec31188563cc880c
x86_64 opencryptoki-libs-3.25.0-4.el9_7.2.x86_64.rpm 74ce40b21016bdd4c4c8384b4f3c1f0e574e0a7f7b842c97aab0714619455a8c
x86_64 opencryptoki-ccatok-3.25.0-4.el9_7.2.x86_64.rpm 7d9b8c247a6c55583c2e6750001d5359c9187c1f1e888f984faad8fec8681bd2
x86_64 opencryptoki-devel-3.25.0-4.el9_7.2.x86_64.rpm ceb7c9809d81cd88cac4c2209b57ffec5a8c5d043e3bbcf22d3f9a9edb1bca44
x86_64 opencryptoki-3.25.0-4.el9_7.2.x86_64.rpm f2286db4aae593a4c092c0022f3308004746975e614c03ba5877a85b7d94a8bd
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.