{"id":"SUSE-SU-2026:22293-1","summary":"Security update for openCryptoki","details":"This update for openCryptoki fixes the following issues\n\nUpgrade openCryptoki to version 3.27 (jsc#PED-14609):\n\n * Add base support for PKCS#11 v3.2.\n * Add support for PKCS#11 v3.2 C_VerifySignature[Init|Update|Final].\n * Add support for PKCS#11 v3.2 C_EncapsulateKey/C_DecapsulateKey.\n * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.2 en-/decapsulate with RSA-PKCS and RSA-OAEP mechanisms.\n * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.2 en-/decapsulate with the ECDH mechanism.\n * Soft/EP11: Add support for PKCS#11 v3.2 en-/decapsulate with the DH-PKCS mechanism.\n * Soft: Add support for PKCS#11 v3.2 ML-DSA and ML-KEM key types and mechanisms (requires OpenSSL 3.5 or later, or\n the OQS-provider must be configured).\n * CCA: Add support for PKCS#11 v3.2 ML-DSA key type and mechanisms (requires CCA v8.4 or later)\n * EP11: Add support for PKCS#11 v3.2 ML-DSA and ML-KEM key types and mechanisms (requires an EP11 host library v4.2 or later,\n and a CEX8P crypto card with firmware v9.6 or later on IBM z17, and v8.39 or later on IBM z16).\n * p11sak: Add support for PKCS#11 v3.2 ML-DSA and ML-KEM key types.\n * Soft/ICA: Add support for PKCS#11 v3.2 mechanisms CKM_ECDH_X_AES_KEY_WRAP and CKM_ECDH_COF_AES_KEY_WRAP.\n * p11sak: Add support for key wrapping with PKCS#11 v3.2 mechanisms CKM_ECDH_X_AES_KEY_WRAP and CKM_ECDH_COF_AES_KEY_WRAP.\n * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.2 mechanism CKM_PUB_KEY_FROM_PRIV_KEY.\n * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.0 Edwards and Montgomery key types and mechanisms.\n * Soft/ICA: Support CKM_ECDH_AES_KEY_WRAP also for Montgomery keys.\n * p11sak: Add support for PKCS#11 v3.0 Edwards and Montgomery key types.\n * Soft: Add support for CKM_ECDH1_COFACTOR_DERIVE.\n * CCA: Add support for additional RSA public exponent values 5, 17, or 257.\n * p11sak: Add option to list-key command to show EP11 session IDs.\n * Make the maximum number of token objects supported configurable.\n * Fixes for CVE-2026-40253, CVE-2026-23893, and CVE-2026-22791.\n * Bug fixes.\n","modified":"2026-06-30T18:24:39.352695233Z","published":"2026-06-25T11:53:53Z","related":["CVE-2026-22791","CVE-2026-23893","CVE-2026-40253"],"upstream":["CVE-2026-22791","CVE-2026-23893","CVE-2026-40253"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202622293-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268745"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-22791"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23893"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40253"}],"affected":[{"package":{"name":"openCryptoki","ecosystem":"SUSE:Linux Micro 6.2","purl":"pkg:rpm/suse/openCryptoki&distro=SUSE%20Linux%20Micro%206.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.27.0-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"openCryptoki":"3.27.0-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22293-1.json"}}],"schema_version":"1.7.5"}