Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
红帽产品勘误 RHSA-2026:4717 - Security Advisory
发布:
2026-03-17
已更新:
2026-03-17

RHSA-2026:4717 - Security Advisory

  • 概述
  • 更新的软件包

概述

Moderate: opencryptoki security update

类型/严重性

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

识别并修复受此公告影响的系统。

查看受影响的系统

标题

An update for opencryptoki is now available for Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

描述

The opencryptoki packages contain version 2.11 of the PKCS#11 API, implemented for IBM Cryptocards, such as IBM 4764 and 4765 crypto cards. These packages includes support for the IBM 4758 Cryptographic CoProcessor (with the PKCS#11 firmware loaded), the IBM eServer Cryptographic Accelerator (FC 4960 on IBM eServer System p), the IBM Crypto Express2 (FC 0863 or FC 0870 on IBM System z), and the IBM CP Assist for Cryptographic Function (FC 3863 on IBM System z). The opencryptoki packages also bring a software token implementation that can be used without any cryptographic hardware. These packages contain the Slot Daemon (pkcsslotd) and general utilities.

Security Fix(es):

  • openCryptoki: openCryptoki: Privilege Escalation or Data Exposure via Symlink Following (CVE-2026-23893)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

解决方案

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

受影响的产品

  • Red Hat Enterprise Linux for x86_64 10 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 10 s390x
  • Red Hat Enterprise Linux for Power, little endian 10 ppc64le
  • Red Hat Enterprise Linux for ARM 64 10 aarch64
  • Red Hat CodeReady Linux Builder for x86_64 10 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le
  • Red Hat CodeReady Linux Builder for ARM 64 10 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x

修复

  • BZ - 2431909 - CVE-2026-23893 openCryptoki: openCryptoki: Privilege Escalation or Data Exposure via Symlink Following

CVE

  • CVE-2026-23893

参考

  • https://access.redhat.com/security/updates/classification/#moderate
注:: 可能有这些软件包的更新版本。 点击软件包名称查看详情。

Red Hat Enterprise Linux for x86_64 10

SRPM
opencryptoki-3.25.0-5.el10_1.2.src.rpm SHA-256: dff526b62a00b728c1d730eba027de252bfce4c98120c3f684815b976457db6d
x86_64
opencryptoki-3.25.0-5.el10_1.2.x86_64.rpm SHA-256: 5c8cf2cd75116646adfaecb17626e2d64af1dd5ad28c59b749a6ec149a87e951
opencryptoki-ccatok-3.25.0-5.el10_1.2.x86_64.rpm SHA-256: f9b1fc9d0eacb51a6b22c32992294dfa1ee35f06728a7fd29edbe5c4b899371f
opencryptoki-ccatok-debuginfo-3.25.0-5.el10_1.2.x86_64.rpm SHA-256: 801f8c6fbe68d0f7b3056ee60415ede927ea31e1bce055cc0d0efe2e0f3abdfe
opencryptoki-debuginfo-3.25.0-5.el10_1.2.x86_64.rpm SHA-256: 029fe62283ec3d82b2c6d8c91b5dda104ab520f6f49e062d5ea03e68c805e75b
opencryptoki-debugsource-3.25.0-5.el10_1.2.x86_64.rpm SHA-256: 915f3ff545df48e76a295c1d4827fe7d15ec6b6997e38c68ccb3502ef469f98f
opencryptoki-icsftok-3.25.0-5.el10_1.2.x86_64.rpm SHA-256: 6425c3ce9e35a9a8a4961dabb9cd768adcb670226e5be41d11435d12a389f138
opencryptoki-icsftok-debuginfo-3.25.0-5.el10_1.2.x86_64.rpm SHA-256: 999084dbc7b87cb04f1b8b1b1d14c0663dcee58dbd3909de2bb8963b11d8bc4d
opencryptoki-libs-3.25.0-5.el10_1.2.x86_64.rpm SHA-256: 321eb969284b42f34ca663d07d67d7ab4781264d626e3e5a85ec9f99d2b7a58a
opencryptoki-libs-debuginfo-3.25.0-5.el10_1.2.x86_64.rpm SHA-256: 2af6e1b6d35250ef2ad1ed287af312ae68837de92071edbf203b1a673f028013
opencryptoki-swtok-3.25.0-5.el10_1.2.x86_64.rpm SHA-256: 8f1f5aa64728d31d783bc5800b2dc01be658d6d2abc6ac4d10189ccc5ae08bfe
opencryptoki-swtok-debuginfo-3.25.0-5.el10_1.2.x86_64.rpm SHA-256: 7f70830174071f13b86663f703e36075d7b8bf0f41731ce5aee8ef4215891b80

Red Hat Enterprise Linux for IBM z Systems 10

SRPM
opencryptoki-3.25.0-5.el10_1.2.src.rpm SHA-256: dff526b62a00b728c1d730eba027de252bfce4c98120c3f684815b976457db6d
s390x
opencryptoki-3.25.0-5.el10_1.2.s390x.rpm SHA-256: d2ecade6842979d7817081ceed838552ea17d816d182bd6637cd94d50e5115b1
opencryptoki-ccatok-3.25.0-5.el10_1.2.s390x.rpm SHA-256: b00b29073a33cb007d0ec635a3c7d2db6b12aa1807e039b5b9f5136fc18b60b3
opencryptoki-ccatok-debuginfo-3.25.0-5.el10_1.2.s390x.rpm SHA-256: dd2168a162fabfc69822a96ed444cb57b689658b08d2b52db0c28b7820b25ac1
opencryptoki-debuginfo-3.25.0-5.el10_1.2.s390x.rpm SHA-256: b18b413861c4fb1adb3f7104e0a7b8e4d3a46da1d5b19b4a45698661e9137dd1
opencryptoki-debugsource-3.25.0-5.el10_1.2.s390x.rpm SHA-256: 24cdd0511f3a40f398e21f5b878d45dda0e012d52f5ddfc4b099024c1a1f63c0
opencryptoki-ep11tok-3.25.0-5.el10_1.2.s390x.rpm SHA-256: 587ea5fd1ffe42c82a1e1e68b141033145976f44099480ee6c2bbe8d5dbf366c
opencryptoki-ep11tok-debuginfo-3.25.0-5.el10_1.2.s390x.rpm SHA-256: 743d0d06ad5e673ceaab80a0bd4c0248493aa5b3c9ca324b8281c5abe5079816
opencryptoki-icatok-3.25.0-5.el10_1.2.s390x.rpm SHA-256: e9c5426dc61660df9e95488e4d570eba0cdd3bf7ce2d1c3def0d07bfaa003d95
opencryptoki-icatok-debuginfo-3.25.0-5.el10_1.2.s390x.rpm SHA-256: f59a13b39ef20fd8fd6c00bf2680548de20aaf7f97afd7bac994eb671afacfe1
opencryptoki-icsftok-3.25.0-5.el10_1.2.s390x.rpm SHA-256: aa2ffd9108ce55af828a2775ac2d3a32a467b83dad1020441214c9540eb56991
opencryptoki-icsftok-debuginfo-3.25.0-5.el10_1.2.s390x.rpm SHA-256: f23b7690d0d5761ad3c633943c07320cd6a1e064f3aec0fbac530f9403ee3a3c
opencryptoki-libs-3.25.0-5.el10_1.2.s390x.rpm SHA-256: 9f05c1561cca26ae87cf1172a762c9d160615d9c54f2e4094c9164c2b66bda51
opencryptoki-libs-debuginfo-3.25.0-5.el10_1.2.s390x.rpm SHA-256: e2a67fb6c408c9e6364a589b547af0828ef8d2bc125a6304782b656fd6444e92
opencryptoki-swtok-3.25.0-5.el10_1.2.s390x.rpm SHA-256: a01d0571b36e68de2143911332c4e9231bab25c47f5ee1e89d19d2380d002a49
opencryptoki-swtok-debuginfo-3.25.0-5.el10_1.2.s390x.rpm SHA-256: 0556e3ccb4ca72217a503cecae61e1348288909db07af1ab31e9ac884c2768bf

Red Hat Enterprise Linux for Power, little endian 10

SRPM
opencryptoki-3.25.0-5.el10_1.2.src.rpm SHA-256: dff526b62a00b728c1d730eba027de252bfce4c98120c3f684815b976457db6d
ppc64le
opencryptoki-3.25.0-5.el10_1.2.ppc64le.rpm SHA-256: c20c9ba4732def90a2dcb2ac1240a2e450c3b3c9f02fb049a7bba6d14c0287e5
opencryptoki-ccatok-3.25.0-5.el10_1.2.ppc64le.rpm SHA-256: fd376dde7559e949a69ec6f0338b73af55ce0e21f6399a974923e70de1825f2e
opencryptoki-ccatok-debuginfo-3.25.0-5.el10_1.2.ppc64le.rpm SHA-256: 4d35f1184ee9583152aa3ecbb4b3ee8fae02e1f8f7bf161be880e0bae7c6ba67
opencryptoki-debuginfo-3.25.0-5.el10_1.2.ppc64le.rpm SHA-256: 9f3ab571e8a6f862a235fac6a8280590766197a0f05245d201512656772e7b77
opencryptoki-debugsource-3.25.0-5.el10_1.2.ppc64le.rpm SHA-256: b68d84140f02dba47c1857866029384fd96e29cdc6e4383a5dd04879167ff293
opencryptoki-icsftok-3.25.0-5.el10_1.2.ppc64le.rpm SHA-256: 4367d190613e851d12831dd10948017cb816a5bc9ba8aefd2d97528a4839b06a
opencryptoki-icsftok-debuginfo-3.25.0-5.el10_1.2.ppc64le.rpm SHA-256: 4610d5c1e6aee9c8e1ffeb7e6d49d4a2eb1d44f8d24d300c20e2546c16584861
opencryptoki-libs-3.25.0-5.el10_1.2.ppc64le.rpm SHA-256: 9da649adeaffa7c45bfaa4e9a1b46a70cc90cf98c6a27905db2b81249ea01aaf
opencryptoki-libs-debuginfo-3.25.0-5.el10_1.2.ppc64le.rpm SHA-256: c41bfeba41385967fad6052de6da48584ccfe8569c52a8f897b8a8e30b3f31de
opencryptoki-swtok-3.25.0-5.el10_1.2.ppc64le.rpm SHA-256: f7c4bf757040f51fcb623e8fc92e072df0f0444f34f6d30c15e2b62f96e7f7a0
opencryptoki-swtok-debuginfo-3.25.0-5.el10_1.2.ppc64le.rpm SHA-256: 5019ff037541be5524401197fcebf0eecec6cc17e6309511782ac542be38fe97

Red Hat Enterprise Linux for ARM 64 10

SRPM
opencryptoki-3.25.0-5.el10_1.2.src.rpm SHA-256: dff526b62a00b728c1d730eba027de252bfce4c98120c3f684815b976457db6d
aarch64
opencryptoki-3.25.0-5.el10_1.2.aarch64.rpm SHA-256: 93de913e7c7f743b770b3173aac6d953f0e792c4524e5a315667831defc1e396
opencryptoki-debuginfo-3.25.0-5.el10_1.2.aarch64.rpm SHA-256: febd65d13a869ff1931106289eddcb2a6748c1d8ecf9ca137ea6ae98149e4ad2
opencryptoki-debugsource-3.25.0-5.el10_1.2.aarch64.rpm SHA-256: 615bdd3a9982e2d772289af0953348ca8df11860468f2009c6c85f61c6080dc1
opencryptoki-icsftok-3.25.0-5.el10_1.2.aarch64.rpm SHA-256: ceb61f419c59d47b23ee3e25280fd8f2b493fdfeac8db860ee0adaee4b40d33c
opencryptoki-icsftok-debuginfo-3.25.0-5.el10_1.2.aarch64.rpm SHA-256: c302a965c57bebeaaf361af6a212976dbbf7d0bc0fc3371e434c0e731c082a14
opencryptoki-libs-3.25.0-5.el10_1.2.aarch64.rpm SHA-256: 6be18c96bd62bb27c31a9c043225cfd2f4dc4a000c434cd113fc0e4789bfc2bb
opencryptoki-libs-debuginfo-3.25.0-5.el10_1.2.aarch64.rpm SHA-256: dee037df814093cd4dc671de2e3eb0040cb346b6039412e6860eb2bcfd2c5644
opencryptoki-swtok-3.25.0-5.el10_1.2.aarch64.rpm SHA-256: 0315d90fd4f826429b8b6c0c2bd46aa46a83246989b86840709712d4d2153c83
opencryptoki-swtok-debuginfo-3.25.0-5.el10_1.2.aarch64.rpm SHA-256: 44c554744f6b577bfbf36b656fbaef9facf70e68b0b0676aabe43c76d3f63ea9

Red Hat CodeReady Linux Builder for x86_64 10

SRPM
x86_64
opencryptoki-ccatok-debuginfo-3.25.0-5.el10_1.2.x86_64.rpm SHA-256: 801f8c6fbe68d0f7b3056ee60415ede927ea31e1bce055cc0d0efe2e0f3abdfe
opencryptoki-debuginfo-3.25.0-5.el10_1.2.x86_64.rpm SHA-256: 029fe62283ec3d82b2c6d8c91b5dda104ab520f6f49e062d5ea03e68c805e75b
opencryptoki-debugsource-3.25.0-5.el10_1.2.x86_64.rpm SHA-256: 915f3ff545df48e76a295c1d4827fe7d15ec6b6997e38c68ccb3502ef469f98f
opencryptoki-devel-3.25.0-5.el10_1.2.x86_64.rpm SHA-256: ebdd0c8b0e8069857ba41bed8e3b98c70ed7648273e7eaaa4741e6e9e2844fb9
opencryptoki-icsftok-debuginfo-3.25.0-5.el10_1.2.x86_64.rpm SHA-256: 999084dbc7b87cb04f1b8b1b1d14c0663dcee58dbd3909de2bb8963b11d8bc4d
opencryptoki-libs-debuginfo-3.25.0-5.el10_1.2.x86_64.rpm SHA-256: 2af6e1b6d35250ef2ad1ed287af312ae68837de92071edbf203b1a673f028013
opencryptoki-swtok-debuginfo-3.25.0-5.el10_1.2.x86_64.rpm SHA-256: 7f70830174071f13b86663f703e36075d7b8bf0f41731ce5aee8ef4215891b80

Red Hat CodeReady Linux Builder for Power, little endian 10

SRPM
ppc64le
opencryptoki-ccatok-debuginfo-3.25.0-5.el10_1.2.ppc64le.rpm SHA-256: 4d35f1184ee9583152aa3ecbb4b3ee8fae02e1f8f7bf161be880e0bae7c6ba67
opencryptoki-debuginfo-3.25.0-5.el10_1.2.ppc64le.rpm SHA-256: 9f3ab571e8a6f862a235fac6a8280590766197a0f05245d201512656772e7b77
opencryptoki-debugsource-3.25.0-5.el10_1.2.ppc64le.rpm SHA-256: b68d84140f02dba47c1857866029384fd96e29cdc6e4383a5dd04879167ff293
opencryptoki-devel-3.25.0-5.el10_1.2.ppc64le.rpm SHA-256: ca6fd16f062478a8ccd2acd96ebedeafe50bb5e5c0d275897ee6669f2e012729
opencryptoki-icsftok-debuginfo-3.25.0-5.el10_1.2.ppc64le.rpm SHA-256: 4610d5c1e6aee9c8e1ffeb7e6d49d4a2eb1d44f8d24d300c20e2546c16584861
opencryptoki-libs-debuginfo-3.25.0-5.el10_1.2.ppc64le.rpm SHA-256: c41bfeba41385967fad6052de6da48584ccfe8569c52a8f897b8a8e30b3f31de
opencryptoki-swtok-debuginfo-3.25.0-5.el10_1.2.ppc64le.rpm SHA-256: 5019ff037541be5524401197fcebf0eecec6cc17e6309511782ac542be38fe97

Red Hat CodeReady Linux Builder for ARM 64 10

SRPM
aarch64
opencryptoki-debuginfo-3.25.0-5.el10_1.2.aarch64.rpm SHA-256: febd65d13a869ff1931106289eddcb2a6748c1d8ecf9ca137ea6ae98149e4ad2
opencryptoki-debugsource-3.25.0-5.el10_1.2.aarch64.rpm SHA-256: 615bdd3a9982e2d772289af0953348ca8df11860468f2009c6c85f61c6080dc1
opencryptoki-devel-3.25.0-5.el10_1.2.aarch64.rpm SHA-256: 03783b9f1a4ffd019b307a80db3e3f24bc9b87caf872a7c3b6a81303d972d3ff
opencryptoki-icsftok-debuginfo-3.25.0-5.el10_1.2.aarch64.rpm SHA-256: c302a965c57bebeaaf361af6a212976dbbf7d0bc0fc3371e434c0e731c082a14
opencryptoki-libs-debuginfo-3.25.0-5.el10_1.2.aarch64.rpm SHA-256: dee037df814093cd4dc671de2e3eb0040cb346b6039412e6860eb2bcfd2c5644
opencryptoki-swtok-debuginfo-3.25.0-5.el10_1.2.aarch64.rpm SHA-256: 44c554744f6b577bfbf36b656fbaef9facf70e68b0b0676aabe43c76d3f63ea9

Red Hat CodeReady Linux Builder for IBM z Systems 10

SRPM
s390x
opencryptoki-ccatok-debuginfo-3.25.0-5.el10_1.2.s390x.rpm SHA-256: dd2168a162fabfc69822a96ed444cb57b689658b08d2b52db0c28b7820b25ac1
opencryptoki-debuginfo-3.25.0-5.el10_1.2.s390x.rpm SHA-256: b18b413861c4fb1adb3f7104e0a7b8e4d3a46da1d5b19b4a45698661e9137dd1
opencryptoki-debugsource-3.25.0-5.el10_1.2.s390x.rpm SHA-256: 24cdd0511f3a40f398e21f5b878d45dda0e012d52f5ddfc4b099024c1a1f63c0
opencryptoki-devel-3.25.0-5.el10_1.2.s390x.rpm SHA-256: d1b63bd35ef0b7810e878399872cb5e78e08f2c149876819ce7df003f72b2623
opencryptoki-ep11tok-debuginfo-3.25.0-5.el10_1.2.s390x.rpm SHA-256: 743d0d06ad5e673ceaab80a0bd4c0248493aa5b3c9ca324b8281c5abe5079816
opencryptoki-icatok-debuginfo-3.25.0-5.el10_1.2.s390x.rpm SHA-256: f59a13b39ef20fd8fd6c00bf2680548de20aaf7f97afd7bac994eb671afacfe1
opencryptoki-icsftok-debuginfo-3.25.0-5.el10_1.2.s390x.rpm SHA-256: f23b7690d0d5761ad3c633943c07320cd6a1e064f3aec0fbac530f9403ee3a3c
opencryptoki-libs-debuginfo-3.25.0-5.el10_1.2.s390x.rpm SHA-256: e2a67fb6c408c9e6364a589b547af0828ef8d2bc125a6304782b656fd6444e92
opencryptoki-swtok-debuginfo-3.25.0-5.el10_1.2.s390x.rpm SHA-256: 0556e3ccb4ca72217a503cecae61e1348288909db07af1ab31e9ac884c2768bf

Red Hat 安全团队联络方式为 secalert@redhat.com。 更多联络细节请参考 https://access.redhat.com/security/team/contact/。

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility