#VU124849 Use of Uninitialized Variable in OpenSC - CVE-2025-13763
Published: April 2, 2026
OpenSC
OpenSC
Description
The vulnerability allows an attacker with physical access to disclose sensitive information, modify data, or cause a denial of service.
The vulnerability exists due to use of uninitialized variable in libopensc when processing crafted input through the fuzz_pkcs15init harness. An attacker with physical access can supply crafted input that triggers use of uninitialized memory to disclose sensitive information, modify data, or cause a denial of service.
The advisory reports 6 use-of-uninitialized-memory cases in functions including sc_asn1_read_tag(), get_cert_len(), asn1_encode_entry(), find_macro(), build_argv(), iasecc_process_fci, and iasecc_sdo_parse(). The reported security relevance is limited, and exploitation requires physical access with high attack complexity according to the provided CVSS vector.