Stack-based buffer overflow in OpenSC - CVE-2025-66215
Published: April 2, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to corrupt memory.
The vulnerability exists due to stack-based buffer overflow in the card-oberthur driver when processing specially crafted responses to APDUs from a crafted USB device or smart card. An attacker with physical access can present a crafted USB device or smart card to corrupt memory.
User interaction is required while a user or administrator uses a token, and the issue affects the oberthur card driver in libopensc.
Affected software
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Anolis OS
Fedora
opensc-debugsource
opensc-debuginfo
opensc
opensc-libs
opensc-doc
How to mitigate CVE-2025-66215
opensc-debugsource - update to 0.19.0-150100.3.34.1
opensc-debuginfo - update to 0.19.0-150100.3.34.1
opensc - update to 0.19.0-150100.3.34.1
opensc - update to 0.26.1-2
opensc-libs - update to 0.26.1-2
opensc-doc - update to 0.26.1-2
opensc - addressed in versions 0.27.1-1.fc42, 0.27.1-1.fc43, 0.27.1-1.fc44