Back

HIGH

opensc: buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package

Published Jun 1, 2023

Description

A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags, where remaining length is wrongly caculated due to moved starting pointer. This leads to possible heap-based buffer oob read. In cases where ASAN is enabled while compiling this causes a crash. Further info leak or more damage is possible.

Affected products

Remediation

No remediation recorded yet.

References (11)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Jun 1, 2023
Updated Nov 3, 2025
Reserved May 30, 2023

CISA Vulnrichment

Updated Jan 9, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Low
Public date May 30, 2023
Bugzilla 2211088

ENISA EUVD

Assigner redhat
Published Jun 1, 2023
Updated Nov 3, 2025

GitHub

No data