Description
A flaw has been found in OpenSC up to 0.27.1. The impacted element is the function setcos_construct_fci_44 of the file src/libopensc/card-setcos.c. Executing a manipulation of the argument type_attr can lead to stack-based buffer overflow. The attack can be launched remotely. This patch is called ad730304052937c32b4eb489a06835ac6123632c. It is best practice to apply a patch to resolve this issue.
Published: 2026-10-01
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Remote code execution via stack buffer overflow
Action: Apply patch
AI Analysis

Impact

The vulnerability resides in the setcos_construct_fci_44 function in OpenSC's card-setcos.c module, where manipulating the type_attr argument can overflow a stack buffer, potentially allowing an attacker to execute arbitrary code. This flaw is a classic stack-based buffer overflow (CWE-119 and CWE-121). The exploit would allow memory corruption, leading to compromised confidentiality, integrity, or availability of any system utilizing the affected OpenSC library.

Affected Systems

All installations of OpenSC up to and including version 0.27.1 are affected. The vulnerability manifests in any environment where the library is invoked for Smart Card operations, especially over networked or remote connections.

Risk and Exploitability

The CVSS base score of 5.1 indicates a medium severity, but the remote attack vector implies that an adversary could target the vulnerable component from outside the host. EPSS data is currently unavailable, and the vulnerability is not yet listed in the CISA KEV catalog, suggesting limited known exploitation at this time. Nevertheless, the lack of patching in exposed systems poses a potential risk that should be mitigated promptly.

Generated by OpenCVE AI on October 1, 2026 at 02:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenSC to a version newer than 0.27.1 (e.g., 0.27.2 or later) that includes the ad730304052937c32b4eb489a06835ac6123632c patch.
  • Restart any services that use OpenSC to ensure the updated library is loaded.
  • If an immediate upgrade is not feasible, restrict or block remote access to Smart Card interfaces until the patch is applied.

Generated by OpenCVE AI on October 1, 2026 at 02:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 01:15:00 +0000

Type Values Removed Values Added
Description A flaw has been found in OpenSC up to 0.27.1. The impacted element is the function setcos_construct_fci_44 of the file src/libopensc/card-setcos.c. Executing a manipulation of the argument type_attr can lead to stack-based buffer overflow. The attack can be launched remotely. This patch is called ad730304052937c32b4eb489a06835ac6123632c. It is best practice to apply a patch to resolve this issue.
Title OpenSC card-setcos.c setcos_construct_fci_44 stack-based overflow
First Time appeared Opensc
Opensc opensc
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:a:opensc:opensc:*:*:*:*:*:*:*:*
Vendors & Products Opensc
Opensc opensc
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 5.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-01T00:45:15.812Z

Reserved: 2026-09-30T19:06:48.961Z

Link: CVE-2026-103531

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T01:16:35.963

Modified: 2026-10-01T02:12:10.020

Link: CVE-2026-103531

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T02:30:18Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-121

    Stack-based Buffer Overflow