Where
-Infinity
0
Severity
1.3
Buffer Overflow
AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C

A flaw has been found in OpenSC up to 0.26.1. This affects the function testkpgencertwrite of the file src/tools/pkcs11-tool.c of the component pkcs11-tool Key Generation Module. This manipulation causes buffer overflow. The attack is possible to be carried out remotely. The complexity of an attack is rather high. It is indicated that the exploitability is difficult. The exploit has been published and may be used. Patch name: 814f745b3b6d100295f65f1935edd33d520d33ab. It is recommended to apply a patch to fix this issue.

1 / 2
Source: MITRE
First published (updated )
Severity
1
Buffer Overflow
AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L

OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in pivprocesshistory() in src/libopensc/card-piv.c that allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device returning a URL field longer than 118 bytes in the Key History Object ASN.1 response.

First published (updated )
Severity
1
Buffer Overflow
AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L

OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the dokeyvalue() function in src/pkcs15init/profile.c that allows attackers to corrupt memory by supplying a crafted profile configuration file. During pkcs15-init invocation, a key value entry beginning with '=' followed by more than sizeof(keybuf) characters is copied into keybuf via memcpy without a length check, causing both stack and heap buffer overruns.

First published (updated )
Severity
6.8
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow WRITE in card-oberthur. The attack requires crafted USB device or smart card that would present the system with specially crafted responses to the APDUs. This issue has been patched in version 0.27.0.

1 / 2
Source: NVD
First published (updated )
Severity
6.8
AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzzpkcs15reader harness causes OpenSC to perform an out-of-bounds heap read in the X.509/SPKI handling path. Specifically, scpkcs15pubkeyfromspkifields() allocates a zero-length buffer and then reads one byte past the end of that allocation. This issue has been patched in version 0.27.0.

1 / 2
Source: MITRE
First published (updated )
Severity
6.8
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sccompacttlvfindtag searches a compact-TLV buffer for a given tag. In compact-TLV, a single byte encodes the tag (high nibble) and value length (low nibble). With a 1-byte buffer {0x0A}, the encoded element claims tag=0 and length=10 but no value bytes follow. Calling sccompacttlvfindtag with search tag 0x00 returns a pointer equal to buf+1 and outlen=10 without verifying that the claimed value length fits within the remaining buffer. In cases where the sccompacttlvfindtag is provided untrusted data (such as being read from cards/files), attackers may be able to influence it to return out-of-bounds pointers leading to downstream memory corruption when subsequent code tries to dereference the pointer. This issue has been patched in version 0.27.0.

1 / 2
Source: NVD
First published (updated )
Severity
6.8
AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow write in GET RESPONSE. The attack requires crafted USB device or smart card that would present the system with specially crafted responses to the APDUs. This issue has been patched in version 0.27.0.

1 / 2
Source: MITRE
First published (updated )

On 2/20/26 8:17 AM, Joe Malcolm wrote: Many will have seen the recent post from Anthropic (1) and associated reporting that says they found 500+ vulnerabilities and lists 3 of them. These three issues don’t appear to have CVEs and two don’t appear in releases. I don’t know if that indicates the maintainers don't agree with the significance of these findings, but I wonder if the other 498+ vulnerabilities also lack CVEs.

1. For OpenSC, the commit appears to be:

https://github.com/OpenSC/OpenSC/ commit/9ab1daf21029dd18f8828d684ee6151d9238edab

There are no disclosed security issues more recent than 2024 at https://github.com/OpenSC/OpenSC/security and the last release was OpenSC 0.26.1. https://github.com/OpenSC/OpenSC/pull/3554 The strcat is a magnet to any static analysis tools and CVEs. Lets get rid of that and replace it with the "safe" strlcat I think this indicates they made the change solely because they were fed up with "security report harassment" and hoped that by making a change they saw as pointless, they could "defang" LLM tooling that reports "use of xxx function could be buggy, you use the function, we shall report it by assuming it is indeed buggy".

-- Eli Schwartz

Many will have seen the recent post from Anthropic (1) and associated reporting that says they found 500+ vulnerabilities and lists 3 of them. These three issues don’t appear to have CVEs and two don’t appear in releases. I don’t know if that indicates the maintainers don't agree with the significance of these findings, but I wonder if the other 498+ vulnerabilities also lack CVEs.

1. For OpenSC, the commit appears to be:

https://github.com/OpenSC/OpenSC/commit/9ab1daf21029dd18f8828d684ee6151d9238edab

There are no disclosed security issues more recent than 2024 at https://github.com/OpenSC/OpenSC/security and the last release was OpenSC 0.26.1.

2. For cgif, the fix is https://github.com/dloebl/cgif/commit/07052febd3a252d30e6f0de67b2ea4f6b9aacddd and it appears in v0.5.1.

4. For ghostscript, the commit appears to be https://github.com/ArtifexSoftware/ghostpdl/commit/4e392a82d1b1780cab85804728317f36a9c4f7f7 which references a nonpublic bug 709080 <https://bugs.ghostscript.com/showbug.cgi?id=709080>. The last release is 10.06.0 (2025-09-09) so there is no release with this fix.

Anthropic’s post: https://red.anthropic.com/2026/zero-days/

Joe

Severity
4
Buffer Overflow

Three stack-based buffer overflow flaws were found in the way OpenSC device drivers for A-Trust ACOS, ACS ACOS5 and STARCOS SPK 2.3 based smart cards processed certain values of card serial number. A local attacker could use this flaw to execute arbitrary code, with the privileges of the user running the opesc-tool or opensc-explorer binaries via a malicious smart card, with specially-crafted value of its serial number, inserted to the system.

References: [1] http://labs.mwrinfosecurity.com/files/Advisories/mwriopensc-get-serial-buffer-overflow2010-12-13.pdf [2] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=607732 [3] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=607427 [4] http://www.h-online.com/open/news/item/When-a-smart-card-can-root-your-computer-1154829.html [5] https://bugs.launchpad.net/ubuntu/+source/opensc/+bug/692483

Upstream changesets: [6] https://www.opensc-project.org/opensc/changeset/4913 [7] https://www.opensc-project.org/opensc/changeset/4912

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203