Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40510

Опубликовано: 29 мая 2026
Источник: redhat
CVSS3: 6.3

Описание

OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device returning a URL field longer than 118 bytes in the Key History Object ASN.1 response.

A flaw was found in OpenSC. A physically present attacker can exploit a stack buffer overflow vulnerability in the piv_process_history() function by presenting a specially crafted Personal Identity Verification (PIV) smart card or USB device. This can lead to memory corruption within the system, potentially causing instability or unexpected behavior.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10openscFix deferred
Red Hat Enterprise Linux 7openscFix deferred
Red Hat Enterprise Linux 8openscFix deferred
Red Hat Enterprise Linux 9openscFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2483280opensc: OpenSC: Memory corruption via crafted PIV smart card

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.8
nvd
2 месяца назад

OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device returning a URL field longer than 118 bytes in the Key History Object ASN.1 response.

msrc
около 2 месяцев назад

OpenSC < 0.27.0-rc1 Stack Buffer Overflow via piv_process_history() in card-piv.c

CVSS3: 3.8
debian
2 месяца назад

OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack bu ...

CVSS3: 3.8
github
2 месяца назад

OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device returning a URL field longer than 118 bytes in the Key History Object ASN.1 response.

6.3 Medium

CVSS3