CVE-2026-10275: OpenSC pkcs11-tool Key Generation pkcs11-tool.c test_kpgen_certwrite buffer overflow

Published Jun 1, 2026
·
Updated

A flaw has been found in OpenSC up to 0.26.1. This affects the function testkpgencertwrite of the file src/tools/pkcs11-tool.c of the component pkcs11-tool Key Generation Module. This manipulation causes buffer overflow. The attack is possible to be carried out remotely. The complexity of an attack is rather high. It is indicated that the exploitability is difficult. The exploit has been published and may be used. Patch name: 814f745b3b6d100295f65f1935edd33d520d33ab. It is recommended to apply a patch to fix this issue.

Other sources

OpenSC pkcs11-tool Key Generation pkcs11-tool.c testkpgencertwrite buffer overflow

Microsoft

Affected Software

3 affected componentsFixes available
OpenSC OpenSC<=0.26.1
Microsoft azl3 opensc 0.27.1-1<0.27.1-2
0.27.1-2
Microsoft azl3 opensc 0.27.1-2<0.27.1-2
0.27.1-2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 0.27.1-2
  2. Upgrade

    Upgrade OpenSC to a version that resolves this vulnerability.

    Fixed in 0.26.1Patch 814f745b3b6d100295f65f1935edd33d520d33ab
  3. Compensating control

    Given the reported remote exploitability, restrict network access to the systems running OpenSC/pkcs11-tool (e.g., limit access to trusted IPs via firewall/ACL) to reduce exposure until the patch is applied.

Event History

Jun 1, 2026
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Jun 5, 2026
Data Sourced
via Microsoft·08:02 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:02 AM
Affected Software
Updated
via Microsoft·08:02 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-2026-10275?

The severity of CVE-2026-10275 is rated as medium with a score of 5.

2

How does CVE-2026-10275 affect OpenSC?

CVE-2026-10275 affects OpenSC versions up to 0.26.1 through a buffer overflow in the pkcs11-tool Key Generation module.

3

How can I mitigate CVE-2026-10275?

To mitigate CVE-2026-10275, update OpenSC to the latest version that addresses this vulnerability.

4

What impact could CVE-2026-10275 have if exploited?

If exploited, CVE-2026-10275 could allow an attacker to execute arbitrary code remotely due to the buffer overflow.

5

What component is vulnerable in CVE-2026-10275?

The vulnerable component in CVE-2026-10275 is the pkcs11-tool Key Generation Module in OpenSC.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203