{"id":"SUSE-SU-2026:21575-1","summary":"Security update for openCryptoki","details":"This update for openCryptoki fixes the following issues\n\nSecurity issue:\n\n- CVE-2026-40253: Updated fix for malformed BER-encoded cryptographic objects\n  (bsc#1262283).\n\nNon security issue:\n\n- Refactored .spec file to fully support transactional and immutable operating systems\n (jsc#PED-14609):\n * Migrated user and group creation (pkcs11, pkcsslotd) from imperative %pre shell commands to\n declarative systemd-sysusers configuration.\n * Replaced manual /var directory tracking and %ghost directives with\n comprehensive systemd-tmpfiles configurations.\n * Implemented dynamic, architecture-specific tmpfiles.d generation to properly provision\n hardware-specific token directories (e.g., ccatok, ep11tok, lite, and HSM_MK_CHANGE).\n- Fixed permissions for /run/opencryptoki within tmpfiles.d to ensure the\n daemon can successfully drop privileges and bind its communication socket.\n * Moved 32-bit and 64-bit shared library symlink creation (such as PKCS11_API.so, stdll, and methods)\n from %post scriptlets into the %install phase,\n ensuring they are correctly packaged and tracked on the read-only /usr partition.\n * Removed legacy /etc/pkcs11 bash migration logic from %post,\n replacing it with a declarative tmpfiles.d symlink rule.\n- Cleaned up scriptlets to only execute transaction-safe macros\n (such as ldconfig and systemd service handlers).\n","modified":"2026-05-12T18:24:39.230814887Z","published":"2026-05-07T09:52:51Z","related":["CVE-2026-40253"],"upstream":["CVE-2026-40253"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202621575-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262283"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263819"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40253"}],"schema_version":"1.7.5"}