#VU121274 Incorrect Calculation of Buffer Size in Opencryptoki - CVE-2026-22791
Published: January 13, 2026
Opencryptoki
Opencryptoki Project
Description
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to a boundary error within the CKM_ECDH_AES_KEY_WRAP implementation in ecdh_aes_key_wrap() function in usr/lib/common/mech_ec.c. A remote attacker can pass a specially crafted public EC key to the application and perform a denial of service attack.