Low severity3.9NVD Advisory· Published Mar 30, 2026· Updated Apr 1, 2026
CVE-2025-66037
CVE-2025-66037
Description
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_pkcs15_reader harness causes OpenSC to perform an out-of-bounds heap read in the X.509/SPKI handling path. Specifically, sc_pkcs15_pubkey_from_spki_fields() allocates a zero-length buffer and then reads one byte past the end of that allocation. This issue has been patched in version 0.27.0.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/OpenSC/OpenSC/security/advisories/GHSA-m58q-rmjm-mmfxnvdExploitVendor Advisory
News mentions
0No linked articles in our index yet.