AZL-105342

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105342.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-105342
Upstream
Published
2026-10-01T01:16:35Z
Modified
2026-10-01T14:17:29Z
Summary
CVE-2026-103531 affecting package opensc 0.27.1-2
Details

A flaw has been found in OpenSC up to 0.27.1. The impacted element is the function setcos_construct_fci_44 of the file src/libopensc/card-setcos.c. Executing a manipulation of the argument type_attr can lead to stack-based buffer overflow. The attack can be launched remotely. This patch is called ad730304052937c32b4eb489a06835ac6123632c. It is best practice to apply a patch to resolve this issue.

References

Affected packages

Azure Linux:3 / opensc

Package

Name
opensc
Purl
pkg:rpm/azure-linux/opensc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.27.1-2

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105342.json"