PT-2026-29080 · Opensc · Opensc

Published

2025-01-01

·

Updated

2026-06-15

·

CVE-2025-49010

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenSC versions prior to 0.27.0
Description OpenSC is a set of open source smart card tools and middleware. A stack-based buffer overflow can occur in the GET RESPONSE function when a user or administrator utilizes a token, allowing an attacker with physical access to the computer to potentially cause a write to the stack. The attack requires a crafted USB device or smart card presenting specially crafted responses to the APDUs.
Recommendations Update to version 0.27.0 or later.

Exploit

Fix

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-49010
GHSA-Q5CF-5WMX-9WH4
OESA-2026-2545
OESA-2026-2546
OPENSUSE-SU-2026:10475-1
SUSE-SU-2026:1477-1
SUSE-SU-2026:21283-1
SUSE-SU-2026:21320-1
SUSE-SU-2026:22114-1
SUSE-SU-2026:22126-1

Affected Products

Opensc