Back

MEDIUM

Opensc: out-of-bounds read in myeid driver handling encryption using symmetric keys

Published Nov 6, 2023

Description

An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or smart card. This flaw allows the attacker to manipulate APDU responses and potentially gain unauthorized access to sensitive data, compromising the system's security.

Affected products

Remediation

Red Hat statement

This CVE does not affect Red Hat Enterprise Linux 8 as the affected functionality was introduced in OpenSC-0.23.0 and RHEL-8 uses OpenSC-0.20.0 and lower versions.

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 6, 2023
Updated Nov 21, 2025
Reserved Aug 25, 2023
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Sep 25, 2023
ENISA EUVD
Assigner redhat
Published Nov 6, 2023
Updated Nov 21, 2025
Exploited since n/a
EUVD-2023-54390