Buffer Overflow Affecting opensc package, versions *


Severity

Recommended
0.0
medium
0
10

Based on CentOS security rating.

Threat Intelligence

EPSS
0.3% (22nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CENTOS10-OPENSC-17352063
  • published17 Jun 2026
  • disclosed1 Jun 2026

Introduced: 1 Jun 2026

NewCVE-2026-10275  (opens in a new tab)
CWE-120  (opens in a new tab)

How to fix?

There is no fixed version for Centos:10 opensc.

NVD Description

Note: Versions mentioned in the description apply only to the upstream opensc package and not the opensc package as distributed by Centos. See How to fix? for Centos:10 relevant fixed versions and status.

A flaw has been found in OpenSC up to 0.26.1. This affects the function test_kpgen_certwrite of the file src/tools/pkcs11-tool.c of the component pkcs11-tool Key Generation Module. This manipulation causes buffer overflow. The attack is possible to be carried out remotely. The complexity of an attack is rather high. It is indicated that the exploitability is difficult. The exploit has been published and may be used. Patch name: 814f745b3b6d100295f65f1935edd33d520d33ab. It is recommended to apply a patch to fix this issue.

CVSS Base Scores

version 3.1