VYPR
Unrated severityNVD Advisory· Published Sep 4, 2018· Updated Aug 5, 2024

CVE-2018-16423

CVE-2018-16423

Description

A double free when handling responses from a smartcard in sc_file_set_sec_attr in libopensc/sc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A double free vulnerability in OpenSC's sc_file_set_sec_attr function allows attackers with a crafted smartcard to cause a denial of service or potentially other impacts.

Vulnerability

A double free vulnerability exists in the sc_file_set_sec_attr function in libopensc/sc.c in OpenSC before version 0.19.0-rc1 [1][2]. The bug occurs when handling responses from a smartcard, leading to a double free of memory.

Exploitation

An attacker must supply a crafted smartcard that sends a malformed response to an APDU command. No authentication is required; the attacker only needs the victim to insert the malicious smartcard into a reader and interact with it using OpenSC.

Impact

Successful exploitation results in a double free, which can cause an application crash (denial of service). The description also notes the possibility of "unspecified other impact," but no further details are provided in the available references [1][2].

Mitigation

The vulnerability is fixed in OpenSC version 0.19.0-rc1, released on 2018-09-04 [4]. Users should upgrade to this version or later. Red Hat also released an advisory (RHSA-2019:2154) for affected Red Hat Enterprise Linux packages [1]. No workarounds are documented.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

12

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.