Executive brief
A vulnerability was found in OpenSC, a library used to interface with smart cards and USB security tokens. By using a specially modified USB device or smart card, an attacker could cause the software to crash or potentially leak sensitive information from the system's memory. This requires physical access to the computer to insert the malicious device.
Technical details
Multiple instances of uninitialized variable usage (CWE-457) were identified in libopensc, specifically within card detection and parsing functions such as iasecc_process_fci, get_cert_len, and cac_is_cert. The vulnerability is triggered when the library processes specially crafted responses (APDUs) from a malicious USB device or smart card. An attacker with physical access can exploit these flaws to read uninitialized memory (information disclosure) or cause a denial-of-service (application crash). The issues were discovered via fuzzing and are addressed in OpenSC version 0.27.0.
Affected products
- OpenSC OpenSC < 0.27.0
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat In-Vehicle Operating System 1
Timeline
- 2025-11-27: disclosed: Initial report in Red Hat Bugzilla
- 2026-03-30: advisory: GitHub Security Advisory published
- 2026-04-23: advisory: NVD publication date