PT-2026-29081 · Opensc · Opensc

CVE-2025-66037

·

Publicado

2025-01-01

·

Atualizado

2026-06-30

CVSS v3.1

6.8

Média

VetorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenSC versions prior to 0.27.0
Description OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, providing a crafted input to the fuzz pkcs15 reader harness results in an out-of-bounds heap read within the X.509/SPKI handling path. Specifically, the sc pkcs15 pubkey from spki fields() function allocates a zero-length buffer and subsequently attempts to read one byte beyond the allocated memory.
Recommendations Update to version 0.27.0 or later.

Exploit

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-81189
CVE-2025-66037
GHSA-M58Q-RMJM-MMFX
OESA-2026-2545
OESA-2026-2546
OPENSUSE-SU-2026:10475-1
OPENSUSE-SU-2026:20967-1
SUSE-SU-2026:1477-1
SUSE-SU-2026:21283-1
SUSE-SU-2026:21320-1
SUSE-SU-2026:22114-1
SUSE-SU-2026:22126-1
SUSE-SU-2026:2657-1
SUSE-SU-2026:2697-1

Produtos afetados

Opensc