USN-8707-1: openCryptoki vulnerabilities
It was discovered that primitive decoders in openCryptoki produced integer underflows when the encoded length was zero. An attacker could possibly use this issue to trigger out-of-bounds reads. (CVE-2026-40253) It was discovered that openCryptoki incorrectly handled symlinks. An attacker in the token-group could possibly use this issue to achieve privilege escalation or access sensitive information. (CVE-2026-23893) It was discovered that the CKM_ECDH_AES_KEY_WRAP implementation had a heap buffer overflow vulnerability. An attacker could possibly use this issue to trigger heap corruption, or denial-of-service. (CVE-2026-22791)
CSIRTS triage
- What
- Integer underflows in decoders cause out-of-bounds reads, symlink handling enables privilege escalation, and heap buffer overflow in CKM_ECDH_AES_KEY_WRAP implementation.
- Who is affected
- Systems using openCryptoki for cryptographic operations, particularly those with token-group members.
- Urgency
- Severity unknown; memory corruption, privilege escalation, and information disclosure across multiple components require prioritized patching.
- Action
- Update openCryptoki to patched version; review token-group membership and audit symlink access in token directories.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch openCryptoki
Get an email when a new openCryptoki advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8707-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-402530.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-238930.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-227910.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-40253 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-23893 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-22791 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from Ubuntu Security Notices
- unknownUSN-8737-1: GNU C Library vulnerabilities2026-09-08
- unknownUSN-8736-1: Perl vulnerabilities2026-09-08
- unknownUSN-8735-1: HSQLDB vulnerability2026-09-08
- unknownUSN-8734-1: PHP vulnerabilities2026-09-07
- unknownUSN-8733-1: Gzip vulnerabilities2026-09-07