CVE-2026-103531
Public on 2026-10-01
Modified on 2026-10-03
Description
A flaw has been found in OpenSC up to 0.27.1. The impacted element is the function setcos_construct_fci_44 of the file src/libopensc/card-setcos.c. Executing a manipulation of the argument type_attr can lead to stack-based buffer overflow. The attack can be launched remotely. This patch is called ad730304052937c32b4eb489a06835ac6123632c. It is best practice to apply a patch to resolve this issue.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | opensc | Pending Fix | ||
| Amazon Linux 2023 | opensc | Pending Fix | ||
| Amazon Linux 2027 Preview | opensc | Pending Fix | ||
| Amazon Linux 2 - Core | openscap | Not Affected | ||
| Amazon Linux 2023 | openscap | Not Affected | ||
| Amazon Linux 2027 Preview | openscap | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 6.8 | CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |