CVE-2026-10275: OpenSC pkcs11-tool Key Generation pkcs11-tool.c test_kpgen_certwrite buffer overflow
A flaw has been found in OpenSC up to 0.26.1. This affects the function testkpgencertwrite of the file src/tools/pkcs11-tool.c of the component pkcs11-tool Key Generation Module. This manipulation causes buffer overflow. The attack is possible to be carried out remotely. The complexity of an attack is rather high. It is indicated that the exploitability is difficult. The exploit has been published and may be used. Patch name: 814f745b3b6d100295f65f1935edd33d520d33ab. It is recommended to apply a patch to fix this issue.
Other sources
OpenSC pkcs11-tool Key Generation pkcs11-tool.c testkpgencertwrite buffer overflow
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.27.1-2 - Upgrade
Upgrade
OpenSCto a version that resolves this vulnerability.Fixed in 0.26.1Patch 814f745b3b6d100295f65f1935edd33d520d33ab - Compensating control
Given the reported remote exploitability, restrict network access to the systems running OpenSC/pkcs11-tool (e.g., limit access to trusted IPs via firewall/ACL) to reduce exposure until the patch is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10275?
The severity of CVE-2026-10275 is rated as medium with a score of 5.
How does CVE-2026-10275 affect OpenSC?
CVE-2026-10275 affects OpenSC versions up to 0.26.1 through a buffer overflow in the pkcs11-tool Key Generation module.
How can I mitigate CVE-2026-10275?
To mitigate CVE-2026-10275, update OpenSC to the latest version that addresses this vulnerability.
What impact could CVE-2026-10275 have if exploited?
If exploited, CVE-2026-10275 could allow an attacker to execute arbitrary code remotely due to the buffer overflow.
What component is vulnerable in CVE-2026-10275?
The vulnerable component in CVE-2026-10275 is the pkcs11-tool Key Generation Module in OpenSC.