Use-after-free in OpenSC - CVE-2024-1454

 

Use-after-free in OpenSC - CVE-2024-1454

Published: March 1, 2024


Vulnerability identifier: #VU86939
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-1454
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to bypass authentication.

The vulnerability exists due to a use-after-free error in the AuthentIC driver in the card enrolment process using pkcs15-init when a user or administrator enrols or modifies cards. An attacker with physical access to the system can use a crafted USB device or smart card to present the system with specially crafted responses to the APDUs to card management operations during enrollment.


Affected software

OpenSC
Amazon Linux AMI
Anolis OS
Fedora
opensc
opensc-doc

How to mitigate CVE-2024-1454

Install updates from vendor's website.

OpenSC - update to 0.25.0 rc1
opensc - update to 0.24.0-1
opensc - update to 0.25.0-1
opensc-doc - update to 0.25.0-1
opensc - addressed in versions 0.25.0-1.fc38, 0.25.0-1.fc39, 0.25.0-1.fc40

External References

Related Security Bulletins