PT-2026-29082 · Opensc · Opensc

CVE-2025-66038

·

Publicado

2025-01-01

·

Atualizado

2026-06-30

CVSS v3.1

6.8

Média

VetorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenSC versions prior to 0.27.0
Description OpenSC is an open source smart card tools and middleware. The sc compacttlv find tag function searches a compact-TLV buffer for a given tag. In compact-TLV, a single byte encodes the tag (high nibble) and value length (low nibble). When provided with a 1-byte buffer, the encoded element claims a tag and length, but no value bytes follow. Calling sc compacttlv find tag with a specific search tag can return an out-of-bounds pointer and a length without verifying that the claimed value length fits within the remaining buffer. If sc compacttlv find tag receives untrusted data, attackers may be able to influence it to return out-of-bounds pointers, leading to memory corruption when subsequent code attempts to dereference the pointer.
Recommendations Versions prior to 0.27.0 should be updated to version 0.27.0 or later.

Exploit

Correção

Buffer Over-read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-66038
GHSA-72X5-FWJX-2459
OPENSUSE-SU-2026:10475-1
OPENSUSE-SU-2026:20967-1
SUSE-SU-2026:1477-1
SUSE-SU-2026:21283-1
SUSE-SU-2026:21320-1
SUSE-SU-2026:22114-1
SUSE-SU-2026:22126-1
SUSE-SU-2026:2657-1
SUSE-SU-2026:2697-1

Produtos afetados

Opensc