CVE-2024-8443: Libopensc: heap buffer overflow in openpgp driver when generating key
A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card with malicious responses to the APDUs during the card enrollment process using the pkcs15-init tool may lead to out-of-bound rights, possibly resulting in arbitrary code execution.
Other sources
The Heap Buffer Overflow vulnerability was identified within the OpenPGP driver during the card enrollment process using the pkcs15-init tool to generate RSA or ECDSA key when a user or administrator enrolls or modifies cards, but it can also be encountered when using the driver for key generation (for example via openpgp-tool).
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/openscto a version that resolves this vulnerability.Fixed in 0.21.0-1+deb11u1Fixed in 0.23.0-0.3+deb12u2Fixed in 0.26.1-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8443?
CVE-2024-8443 is classified as a high severity vulnerability primarily due to its potential to cause a heap-based buffer overflow.
How do I fix CVE-2024-8443?
To mitigate CVE-2024-8443, update your OpenSC and Red Hat Enterprise Linux installations to the latest patched versions.
What software is affected by CVE-2024-8443?
CVE-2024-8443 affects OpenSC and various versions of Red Hat Enterprise Linux including 7.0, 8.0, and 9.0.
What are the potential consequences of CVE-2024-8443?
Exploitation of CVE-2024-8443 may lead to out-of-bounds write conditions, potentially compromising system integrity and security.
Who should be concerned about CVE-2024-8443?
Users and administrators of OpenSC and Red Hat Enterprise Linux should be especially vigilant regarding CVE-2024-8443 due to its significant security implications.