PT-2026-29081 · Opensc · Opensc
Published
2026-03-30
·
Updated
2026-03-30
·
CVE-2025-66037
CVSS v3.1
3.9
Low
| AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L |
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz pkcs15 reader harness causes OpenSC to perform an out-of-bounds heap read in the X.509/SPKI handling path. Specifically, sc pkcs15 pubkey from spki fields() allocates a zero-length buffer and then reads one byte past the end of that allocation. This issue has been patched in version 0.27.0.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opensc