Back

MEDIUM

OpenSC: Out of Bounds vulnerability

Published Mar 30, 2026

Description

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_pkcs15_reader harness causes OpenSC to perform an out-of-bounds heap read in the X.509/SPKI handling path. Specifically, sc_pkcs15_pubkey_from_spki_fields() allocates a zero-length buffer and then reads one byte past the end of that allocation. This issue has been patched in version 0.27.0.

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Mar 30, 2026
Updated Mar 30, 2026
Reserved Nov 21, 2025

CISA Vulnrichment

Updated Mar 30, 2026

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

Severity Low
Public date Mar 30, 2026
Bugzilla 2453122

ENISA EUVD

Assigner GitHub_M
Published Mar 30, 2026
Updated Mar 30, 2026

GitHub

No data