Unrated severityOSV Advisory· Published Nov 6, 2023· Updated Nov 6, 2025
Opensc: multiple memory issues with pkcs15-init (enrollment tool)
CVE-2023-40661
Description
Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user or administrator enrolls cards. To take advantage of these flaws, an attacker must have physical access to the computer system and employ a custom-crafted USB device or smart card to manipulate responses to APDUs. This manipulation can potentially allow compromise key generation, certificate loading, and other card management operations during enrollment.
Affected products
1- Range: 0.12.2, 0.12.2-rc1, 0.13.0, …
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- access.redhat.com/errata/RHSA-2023:7876mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2023:7879mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/security/cve/CVE-2023-40661mitrevdb-entryx_refsource_REDHAT
- bugzilla.redhat.com/show_bug.cgimitreissue-trackingx_refsource_REDHAT
- github.com/OpenSC/OpenSC/issues/2792mitre
- github.com/OpenSC/OpenSC/releases/tag/0.24.0-rc1mitre
News mentions
0No linked articles in our index yet.