OESA-2026-2546

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-2546
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-2546.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-2546
Upstream
Published
2026-06-05T15:48:18Z
Modified
2026-06-05T16:00:31.760281872Z
Summary
opensc security update
Details

OpenSC provides a set of libraries and utilities to work with smart cards. Its main focus is on cards that support cryptographic operations, and facilitate their use in security applications such as authentication, mail encryption and digital signatures. OpenSC implements the standard APIs to smart cards, e.g. PKCS#11 API, Windows’ Smart Card Minidriver and macOS Tokend.

Security Fix(es):

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow write in GET RESPONSE. The attack requires crafted USB device or smart card that would present the system with specially crafted responses to the APDUs. This issue has been patched in version 0.27.0.(CVE-2025-49010)

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzzpkcs15reader harness causes OpenSC to perform an out-of-bounds heap read in the X.509/SPKI handling path. Specifically, scpkcs15pubkeyfromspki_fields() allocates a zero-length buffer and then reads one byte past the end of that allocation. This issue has been patched in version 0.27.0.(CVE-2025-66037)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:24.03-LTS-SP3 / opensc

Package

Name
opensc
Purl
pkg:rpm/openEuler/opensc&distro=openEuler-24.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.23.0-8.oe2403sp3

Ecosystem specific

{
    "src": [
        "opensc-0.23.0-8.oe2403sp3.src.rpm"
    ],
    "aarch64": [
        "opensc-0.23.0-8.oe2403sp3.aarch64.rpm",
        "opensc-debuginfo-0.23.0-8.oe2403sp3.aarch64.rpm",
        "opensc-debugsource-0.23.0-8.oe2403sp3.aarch64.rpm",
        "opensc-help-0.23.0-8.oe2403sp3.aarch64.rpm"
    ],
    "x86_64": [
        "opensc-0.23.0-8.oe2403sp3.x86_64.rpm",
        "opensc-debuginfo-0.23.0-8.oe2403sp3.x86_64.rpm",
        "opensc-debugsource-0.23.0-8.oe2403sp3.x86_64.rpm",
        "opensc-help-0.23.0-8.oe2403sp3.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2546.json"