<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Pkcs11 on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/pkcs11/</link><description>Recent content in Pkcs11 on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Thu, 19 Jun 2025 08:40:27 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/pkcs11/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-10275: OpenSC pkcs11-tool Buffer Overflow</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-10275-opensc-pkcs11-tool-buffer-overflow-azure/</link><pubDate>Fri, 19 Jun 2026 08:40:27 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-10275-opensc-pkcs11-tool-buffer-overflow-azure/</guid><description>CVE-2026-10275 is a buffer overflow in OpenSC pkcs11-tool affecting key generation. Learn the risk to Azure and hybrid HSM environments and how to mitigate</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-10275">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-10275 is a buffer overflow vulnerability in OpenSC&rsquo;s pkcs11-tool, specifically within the key generation and certificate writing functionality in pkcs11-tool.c. The flaw could allow an attacker to corrupt memory during PKCS#11 cryptographic operations, potentially leading to arbitrary code execution or service crashes. This matters because OpenSC is widely used to interact with hardware security modules (HSMs) and smart cards, including in Azure and hybrid environments.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Audit your Azure and on-premises environments for any workloads or pipelines using OpenSC&rsquo;s pkcs11-tool — particularly those interacting with HSMs, smart cards, or PKCS#11 interfaces — and apply vendor patches as soon as they are available. Restrict access to key generation tooling to least-privilege service accounts and consider isolating these operations within hardened CI/CD environments.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-10275">CVE-2026-10275 OpenSC pkcs11-tool Key Generation pkcs11-tool.c test_kpgen_certwrite buffer overflow</a></p>
]]></content:encoded></item><item><title>CVE-2026-42014: GnuTLS Use-After-Free on Azure</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-42014-gnutls-use-after-free-pkcs11-azure/</link><pubDate>Fri, 19 Jun 2026 08:01:29 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-42014-gnutls-use-after-free-pkcs11-azure/</guid><description>CVE-2026-42014 is a use-after-free flaw in GnuTLS affecting PKCS#11 token PIN handling. Azure workloads using GnuTLS should patch immediately.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42014">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-42014 is a use-after-free vulnerability in GnuTLS, a widely used cryptographic library, specifically in the function responsible for setting PKCS#11 token PINs. Use-after-free flaws occur when a programme continues to use memory after it has been freed, potentially allowing attackers to execute arbitrary code or cause a crash. This matters because GnuTLS underpins TLS/SSL operations in many Linux-based workloads, including those running on Azure.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Identify any Azure Linux VMs, containers, or services that use GnuTLS with PKCS#11 hardware security module (HSM) or token-based authentication, and prioritise patching the GnuTLS library to the remediated version. If patching cannot be applied immediately, consider restricting access to PKCS#11 token management interfaces as a compensating control.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42014">CVE-2026-42014 Gnutls: fix use-after-free in gnutls_pkcs11_token_set_pin</a></p>
]]></content:encoded></item></channel></rss>