OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b,...
Low severity
Unreviewed
Published
May 29, 2026
to the GitHub Advisory Database
•
Updated May 29, 2026
Description
Published by the National Vulnerability Database
May 29, 2026
Published to the GitHub Advisory Database
May 29, 2026
Last updated
May 29, 2026
OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device returning a URL field longer than 118 bytes in the Key History Object ASN.1 response.
References