Updated opensc packages fix security vulnerabilities
Publication date: 18 Jun 2026Modification date: 18 Jun 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-13763 , CVE-2025-49010 , CVE-2025-66037 , CVE-2025-66038 , CVE-2025-66215
Description
CVE-2025-66038 Memory corruption via improper compact-TLV length
validation
CVE-2025-66215 Stack-buffer-overflow with physical access via crafted
smart card or USB device
CVE-2025-49010 Stack-buffer-overflow via crafted smart card or USB
device responses
CVE-2025-66037 Out-of-bounds read via crafted input
CVE-2025-13763 Several uses of potentially uninitialized memory detected
by fuzzers
References
- https://bugs.mageia.org/show_bug.cgi?id=35319
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/3VEH2KIGJ2SHJ7FWKNUDZSA2JUHQFRZS/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2WSLOFM35Z6Y4PLTNF7MFB4JO2WJAIMX/
- https://www.cve.org/CVERecord?id=CVE-2025-13763
- https://www.cve.org/CVERecord?id=CVE-2025-49010
- https://www.cve.org/CVERecord?id=CVE-2025-66037
- https://www.cve.org/CVERecord?id=CVE-2025-66038
- https://www.cve.org/CVERecord?id=CVE-2025-66215
SRPMS
9/core
- opensc-0.25.0-1.2.mga9