REDHAT-BUG-2417581: Low severity OpenSC libopensc vulnerability
Published Nov 27, 2025
·Updated
Multiple issues with uninitialized variables were found in libopensc that may lead to information disclosure or application crash. An attack requires a crafted USB device or smart card that would present the system with specially crafted responses to the APDUs
Affected Software
1 affected component
OpenSC libopensc
Event History
Nov 27, 2025
Data Sourced
via Red Hat·02:34 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2417581?
The severity of REDHAT-BUG-2417581 is classified as low.
2
What issues does REDHAT-BUG-2417581 address in libopensc?
REDHAT-BUG-2417581 addresses multiple issues with uninitialized variables in libopensc.
3
What could be the potential impact of exploiting REDHAT-BUG-2417581?
Exploiting REDHAT-BUG-2417581 could lead to information disclosure or an application crash.
4
What is required to exploit the vulnerability identified in REDHAT-BUG-2417581?
A crafted USB device or smart card presenting specially crafted responses to the APDUs is required to exploit this vulnerability.
5
How can I mitigate the risks associated with REDHAT-BUG-2417581?
Mitigation can be achieved by ensuring that libopensc is updated to a version that resolves the uninitialized variables issue.