CVE-2026-10275

EUVD-2026-33680
A flaw has been found in OpenSC up to 0.26.1. This affects the function test_kpgen_certwrite of the file src/tools/pkcs11-tool.c of the component pkcs11-tool Key Generation Module. This manipulation causes buffer overflow. The attack is possible to be carried out remotely. The complexity of an attack is rather high. It is indicated that the exploitability is difficult. The exploit has been published and may be used. Patch name: 814f745b3b6d100295f65f1935edd33d520d33ab. It is recommended to apply a patch to fix this issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 21.72%
Debian logo
Debian Releases
Debian Product
Codename
opensc
bookworm
no-dsa
bullseye
postponed
bullseye (security)
vulnerable
forky
0.27.1-2
fixed
sid
0.27.1-2
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
opensc
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
xenial
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
opensc
Amazon Linux 2
0:0.19.0-6.amzn2.0.3
fixed
Amazon Linux 2023
0:0.24.0-1.amzn2023.0.5
fixed
opensc-debuginfo
Amazon Linux 2
0:0.19.0-6.amzn2.0.3
fixed
Amazon Linux 2023
0:0.24.0-1.amzn2023.0.5
fixed
opensc-debugsource
Amazon Linux 2023
0:0.24.0-1.amzn2023.0.5
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
opensc
Azure Linux 3.0
0:0.27.1-2.azl3
fixed