A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card with malicious responses to the APDUs during the card enrollment process using the `pkcs15-init` tool may lead to out-of-bound rights, possibly resulting in arbitrary code execution.
CVSS Details
- CVSS 3.1 Base Score: 2.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade opensc | Aug 8, 2025 | Sep 10, 2024 |
| Amazon_linux_2023 | — | Upgrade openscUpgrade opensc-debuginfoUpgrade opensc-debugsource | Feb 17, 2025 | Sep 4, 2024 |
| Debian | — | Upgrade opensc | Dec 30, 2024 | Sep 10, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 10, 2024 |
| Suse | — | Upgrade openscUpgrade opensc-32bit | Dec 31, 2024 | Sep 10, 2024 |
| Ubuntu | — | Upgrade opensc-pkcs11Upgrade opensc-pkcs11 (Ubuntu Pro)Upgrade openscUpgrade opensc (Ubuntu Pro) | Mar 13, 2025 | Sep 10, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub