Critical Vulnerabilities in openCryptoki Affecting Ubuntu Systems

Critical Vulnerabilities in openCryptoki Affecting Ubuntu Systems

First seen 27 Aug 2026, 17:17 UTC UbuntuLinuxsecurity 57.9

Article Content

Browse articles
ThreatCluster

Two significant vulnerabilities were discovered in openCryptoki, a PKCS#11 Cryptographic Token Interface implementation. CVE-2026-40253 involves integer underflows that could lead to out-of-bounds reads, while CVE-2026-23893 allows privilege escalation through improper symlink handling. Both vulnerabilities affect Ubuntu 24.04 and 22.04 LTS systems. Attackers in the token-group could exploit these flaws to access sensitive information or escalate privileges. The issues were disclosed on August 27, 2026, and can be mitigated by updating to the latest package versions. A standard system update is recommended for all affected users. The vulnerabilities were published in early 2026, with the first being reported on April 16 and the second on January 22. Immediate action is advised to protect systems from potential exploitation.

Key Points: • Two critical vulnerabilities in openCryptoki were disclosed, affecting Ubuntu systems. • CVE-2026-40253 allows out-of-bounds reads, while CVE-2026-23893 enables privilege escalation. • Users should update their systems immediately to mitigate these vulnerabilities.

Timeline

2026-01-22
CVE-2026-23893 published
Vulnerability discovered in openCryptoki related to symlink handling, allowing privilege escalation.
Linuxsecurity
2026-04-16
CVE-2026-40253 published
Integer underflows in openCryptoki discovered, potentially leading to out-of-bounds reads.
Linuxsecurity
2026-08-27
Vulnerabilities disclosed
Ubuntu released advisory USN-8686-1 detailing critical vulnerabilities in openCryptoki.
Ubuntu