SUSE alert openSUSE-SU-2026:21059-1 (opencryptoki)
| From: | null@suse.de | |
| To: | security-announce@lists.opensuse.org | |
| Subject: | openSUSE-SU-2026:21059-1: important: Security update for openCryptoki | |
| Date: | Tue, 30 Jun 2026 09:48:09 +0200 | |
| Message-ID: | <20260630074809.1F92BFF7C@maintenance.suse.de> | |
| Archive-link: | Article |
openSUSE security update: security update for opencryptoki ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21059-1 Rating: important References: * bsc#1268745 Cross-References: * CVE-2026-22791 * CVE-2026-23893 * CVE-2026-40253 CVSS scores: * CVE-2026-22791 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-22791 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-23893 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L * CVE-2026-40253 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40253 ( SUSE ): 7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 3 vulnerabilities and has one bug fix can now be installed. Description: This update for openCryptoki fixes the following issues Upgrade openCryptoki to version 3.27 (jsc#PED-14609): * Add base support for PKCS#11 v3.2. * Add support for PKCS#11 v3.2 C_VerifySignature[Init|Update|Final]. * Add support for PKCS#11 v3.2 C_EncapsulateKey/C_DecapsulateKey. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.2 en-/decapsulate with RSA-PKCS and RSA-OAEP mechanisms. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.2 en-/decapsulate with the ECDH mechanism. * Soft/EP11: Add support for PKCS#11 v3.2 en-/decapsulate with the DH-PKCS mechanism. * Soft: Add support for PKCS#11 v3.2 ML-DSA and ML-KEM key types and mechanisms (requires OpenSSL 3.5 or later, or the OQS-provider must be configured). * CCA: Add support for PKCS#11 v3.2 ML-DSA key type and mechanisms (requires CCA v8.4 or later) * EP11: Add support for PKCS#11 v3.2 ML-DSA and ML-KEM key types and mechanisms (requires an EP11 host library v4.2 or later, and a CEX8P crypto card with firmware v9.6 or later on IBM z17, and v8.39 or later on IBM z16). * p11sak: Add support for PKCS#11 v3.2 ML-DSA and ML-KEM key types. * Soft/ICA: Add support for PKCS#11 v3.2 mechanisms CKM_ECDH_X_AES_KEY_WRAP and CKM_ECDH_COF_AES_KEY_WRAP. * p11sak: Add support for key wrapping with PKCS#11 v3.2 mechanisms CKM_ECDH_X_AES_KEY_WRAP and CKM_ECDH_COF_AES_KEY_WRAP. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.2 mechanism CKM_PUB_KEY_FROM_PRIV_KEY. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.0 Edwards and Montgomery key types and mechanisms. * Soft/ICA: Support CKM_ECDH_AES_KEY_WRAP also for Montgomery keys. * p11sak: Add support for PKCS#11 v3.0 Edwards and Montgomery key types. * Soft: Add support for CKM_ECDH1_COFACTOR_DERIVE. * CCA: Add support for additional RSA public exponent values 5, 17, or 257. * p11sak: Add option to list-key command to show EP11 session IDs. * Make the maximum number of token objects supported configurable. * Fixes for CVE-2026-40253, CVE-2026-23893, and CVE-2026-22791. * Bug fixes. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1080=1 Package List: - openSUSE Leap 16.0: openCryptoki-3.27.0-160000.1.1 openCryptoki-64bit-3.27.0-160000.1.1 openCryptoki-devel-3.27.0-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2026-22791.html * https://www.suse.com/security/cve/CVE-2026-23893.html * https://www.suse.com/security/cve/CVE-2026-40253.html
