CVE-2025-13763: Libopensc: opensc: multiple uses of uninitialized variable
Multiple issues with uninitialized variables were found in libopensc that may lead to information disclosure or application crash. An attack requires a crafted USB device or smart card that would present the system with specially crafted responses to the APDUs
Other sources
Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application crash. An attack requires a crafted USB device or smart card that would present the system with specially crafted responses to the APDUs
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13763?
The severity of CVE-2025-13763 is considered high due to potential information disclosure and application crashes.
How do I fix CVE-2025-13763?
To fix CVE-2025-13763, update to the latest version of the affected libopensc software or apply the relevant patches.
What could an attacker do with CVE-2025-13763?
An attacker could exploit CVE-2025-13763 by using a crafted USB device or smart card to trigger the exploitation of uninitialized variables.
Which software is affected by CVE-2025-13763?
CVE-2025-13763 affects OpenSC libopensc and Microsoft azl3 opensc 0.26.1-1.
What are the potential consequences of CVE-2025-13763?
The potential consequences of CVE-2025-13763 include information leaks and crashes of applications utilizing the libopensc library.