Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-81186.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-81186
Upstream
Published
2026-03-30T18:16:18Z
Modified
2026-08-28T17:47:55Z
Summary
CVE-2025-66215 affecting package opensc for versions less than 0.27.1-1
Details

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow WRITE in card-oberthur. The attack requires crafted USB device or smart card that would present the system with specially crafted responses to the APDUs. This issue has been patched in version 0.27.0.

References

Affected packages

Azure Linux:3 / opensc

Package

Name
opensc
Purl
pkg:rpm/azure-linux/opensc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.27.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-81186.json"