PT-2026-44841 · Opensc · Opensc

·

CVE-2026-40528

·

Published

2026-05-29

·

Updated

2026-07-21

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenSC versions prior to 0.27.0
Description A stack and heap buffer overrun occurs in the do key value() function within src/pkcs15init/profile.c. This issue allows memory corruption when a crafted profile configuration file is supplied. During the invocation of pkcs15-init, a key value entry starting with '=' followed by more than the size of keybuf is copied into keybuf using memcpy without a length check.
Recommendations Update to version 0.27.0 or apply the fix from commit 0358817.

Exploit

Fix

Stack Overflow

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40528
OPENSUSE-SU-2026:11022-1
SUSE-SU-2026:22103-1
SUSE-SU-2026:22139-1
SUSE-SU-2026:2657-1
SUSE-SU-2026:2697-1

Affected Products

Opensc