PT-2026-29081 · Opensc · Opensc

Published

2026-03-30

·

Updated

2026-03-30

·

CVE-2025-66037

CVSS v3.1

3.9

Low

AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz pkcs15 reader harness causes OpenSC to perform an out-of-bounds heap read in the X.509/SPKI handling path. Specifically, sc pkcs15 pubkey from spki fields() allocates a zero-length buffer and then reads one byte past the end of that allocation. This issue has been patched in version 0.27.0.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2025-66037

Affected Products

Opensc