A flaw has been found in OpenSC up to 0.27.1. The impacted element is the function setcos_construct_fci_44 of the file src/libopensc/card-setcos.c. Executing a manipulation of the argument type_attr can lead to stack-based buffer overflow. The attack can be launched remotely. This patch is called ad730304052937c32b4eb489a06835ac6123632c. It is best practice to apply a patch to resolve this issue.
{
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-119",
"CWE-121"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103531.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103531.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"188444882791401343814308368087227449773",
"255287473414578895801233644686997904169",
"199720571051964386185314939703604722375",
"262364367775997473953856059706205532802",
"167309018626210559516864418781908588900",
"56660642277665989202368885092511930793",
"206291762425855415636357188335520884140",
"168146349159072093215139798962742728625",
"265098098848641978286030226391255275832",
"309382543158221163977322538698882509383"
],
"threshold": 0.9
},
"id": "CVE-2026-103531-6d03cb2f",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/opensc/opensc/commit/ad730304052937c32b4eb489a06835ac6123632c",
"target": {
"file": "src/libopensc/card-setcos.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "294147007155743954127474483399428493291",
"length": 2856
},
"id": "CVE-2026-103531-9217ea0f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/opensc/opensc/commit/ad730304052937c32b4eb489a06835ac6123632c",
"target": {
"file": "src/libopensc/card-setcos.c",
"function": "setcos_construct_fci_44"
}
}
]
"2026-10-02T08:13:50Z"