Use-after-free in OpenSC - CVE-2024-1454
Published: March 1, 2024
Vulnerability details
The vulnerability allows an attacker to bypass authentication.
The vulnerability exists due to a use-after-free error in the AuthentIC driver in the card enrolment process using pkcs15-init when a user or administrator enrols or modifies cards. An attacker with physical access to the system can use a crafted USB device or smart card to present the system with specially crafted responses to the APDUs to card management operations during enrollment.
Affected software
Amazon Linux AMI
Anolis OS
Fedora
opensc
opensc-doc
How to mitigate CVE-2024-1454
opensc - update to 0.24.0-1
opensc - update to 0.25.0-1
opensc-doc - update to 0.25.0-1
opensc - addressed in versions 0.25.0-1.fc38, 0.25.0-1.fc39, 0.25.0-1.fc40