yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2023-5992
Component Overview
Vulnerability Overview
Name
CVE-2023-5992
Source
NVD (
link
)
Debian (
link
)
Description
A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.
CWEs
CWE-203
CWE-203
Published Date
Jan 31, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://access.redhat.com/errata/RHSA-2024:0966
Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:0967
Third Party Advisory
https://access.redhat.com/security/cve/CVE-2023-5992
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2248685
Issue Tracking
https://github.com/OpenSC/OpenSC/wiki/CVE-2023-5992
Vendor Advisory
https://www.usenix.org/system/files/usenixsecurity24-shagam.pdf
Exploit
https://access.redhat.com/errata/RHSA-2024:0966
Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:0967
Third Party Advisory
https://access.redhat.com/security/cve/CVE-2023-5992
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2248685
Issue Tracking
https://github.com/OpenSC/OpenSC/wiki/CVE-2023-5992
Vendor Advisory
Analysis
#
Affected Component
Analysis
opensc
Exploitable
Vulnerability Ratings
#
5.6
CVSSv31
5.9
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
opensc
buildroot
2025.02.x
0.27.1
Not Affected
opensc
buildroot
master
0.27.1
Not Affected
opensc
openwrt
master
0.27.1-r1
Not Affected
opensc
openwrt
openwrt-25.12
0.26.1-r1
Not Affected
opensc
yocto
master
0.27.1
Not Affected
opensc
yocto
scarthgap
0.25.1
Not Affected