CVE-2026-103531
Received Received - Intake

Stack-Based Buffer Overflow in OpenSC

Vulnerability report for CVE-2026-103531, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulDB

Description

A flaw has been found in OpenSC up to 0.27.1. The impacted element is the function setcos_construct_fci_44 of the file src/libopensc/card-setcos.c. Executing a manipulation of the argument type_attr can lead to stack-based buffer overflow. The attack can be launched remotely. This patch is called ad730304052937c32b4eb489a06835ac6123632c. It is best practice to apply a patch to resolve this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
opensc opensc to 0.27.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CWE-119 The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-103531 is a stack-based buffer overflow in OpenSC up to version 0.27.1. The flaw exists in the setcos_construct_fci_44 function in src/libopensc/card-setcos.c. It occurs when the function copies file attributes like type_attr into a fixed 64-byte stack buffer without validating their lengths. If an attribute exceeds 64 bytes, it causes a buffer overflow that can be triggered remotely.

Detection Guidance

To detect this vulnerability, check the version of OpenSC installed on your system. If it is version 0.27.1 or earlier, the system is vulnerable. Use commands like 'opensc-tool --version' or 'dpkg -l | grep opensc' (for Debian-based systems) to verify the installed version.

Impact Analysis

This vulnerability could allow remote attackers to execute arbitrary code or cause denial-of-service conditions on systems using vulnerable OpenSC versions. It may lead to unauthorized access, data corruption, or system crashes if exploited through malicious smart cards or crafted inputs.

Compliance Impact

This vulnerability could potentially impact compliance with standards like GDPR and HIPAA by enabling remote attacks that exploit stack-based buffer overflows in OpenSC. If exploited, it may lead to unauthorized data access, modification, or denial of service, which are critical risks under these regulations. The lack of input validation in the setcos_construct_fci_44 function increases exposure to such attacks.

Mitigation Strategies

Immediately update OpenSC to the latest patched version. Apply the patch from commit ad730304052937c32b4eb489a06835ac6123632c or upgrade to a version beyond 0.27.1. If updating is not possible, restrict access to systems using OpenSC to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103531. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart