#VU124850 Stack-based buffer overflow in OpenSC - CVE-2025-66215
Published: April 2, 2026
OpenSC
OpenSC
Description
The vulnerability allows an attacker with physical access to corrupt memory.
The vulnerability exists due to stack-based buffer overflow in the card-oberthur driver when processing specially crafted responses to APDUs from a crafted USB device or smart card. An attacker with physical access can present a crafted USB device or smart card to corrupt memory.
User interaction is required while a user or administrator uses a token, and the issue affects the oberthur card driver in libopensc.