CVE-2025-66038: OpenSC: `sc_compacttlv_find_tag` can return out-of-bounds pointers

Published Mar 30, 2026
·
Updated

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sccompacttlvfindtag searches a compact-TLV buffer for a given tag. In compact-TLV, a single byte encodes the tag (high nibble) and value length (low nibble). With a 1-byte buffer {0x0A}, the encoded element claims tag=0 and length=10 but no value bytes follow. Calling sccompacttlvfindtag with search tag 0x00 returns a pointer equal to buf+1 and outlen=10 without verifying that the claimed value length fits within the remaining buffer. In cases where the sccompacttlvfindtag is provided untrusted data (such as being read from cards/files), attackers may be able to influence it to return out-of-bounds pointers leading to downstream memory corruption when subsequent code tries to dereference the pointer. This issue has been patched in version 0.27.0.

Other sources

OpenSC: sccompacttlvfindtag can return out-of-bounds pointers

Microsoft

Affected Software

6 affected componentsFixes available
OpenSC OpenSC<0.27.0
Opensc Project Opensc<0.27.0
Microsoft azl3 opensc 0.26.1-1
Microsoft azl3 opensc 0.26.1-1<0.27.1-1
0.27.1-1
Microsoft azl3 opensc 0.27.1-1<0.27.1-1
0.27.1-1
Microsoft azl3 opensc 0.27.1-2<0.27.1-1
0.27.1-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 0.27.1-1
  2. Upgrade

    Upgrade OpenSC (sc_compacttlv_find_tag) to a version that resolves this vulnerability.

    Fixed in 0.27.0

Event History

Mar 30, 2026
CVE Published
via MITRE·05:03 PM
Data Sourced
via MITRE·05:03 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 1, 2026
Data Sourced
via Microsoft·08:14 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:14 AM
DescriptionSeverityWeakness
Updated
via Microsoft·08:14 AM
Affected Software
Updated
via Microsoft·08:14 AM
DescriptionSeverity
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-66038?

CVE-2025-66038 has a severity rating that indicates a risk of out-of-bounds memory access in the OpenSC library, which can lead to potential exploitation.

2

How do I fix CVE-2025-66038?

To resolve CVE-2025-66038, you should upgrade your OpenSC version to 0.27.0 or later to eliminate the vulnerability.

3

What systems are affected by CVE-2025-66038?

CVE-2025-66038 affects all versions of OpenSC prior to 0.27.0.

4

What type of vulnerability is CVE-2025-66038?

CVE-2025-66038 is classified as a memory corruption vulnerability due to out-of-bounds pointer dereference.

5

Is there a workaround for CVE-2025-66038?

There are no known workarounds for CVE-2025-66038; the best course of action is to update to the fixed version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
CVE-2025-66038 - OpenSC: `sc_compacttlv_find_tag` can return out-of-bounds pointers - SecAlerts