Logo
vulnerabilityCVE-2026-40510
Name
CVE-2026-40510
Source
NVD ( link)Debian ( link)
Description
OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device returning a URL field longer than 118 bytes in the Key History Object ASN.1 response.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
opensc
Exploitable

Vulnerability Ratings#


1
CVSSv4
3.8
CVSSv31
6.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
0.27.1
Not Affected
buildroot
master
0.27.1
Not Affected
openwrt
master
0.27.1-r1
Not Affected
openwrt
openwrt-25.12
0.26.1-r1
Exploitable
yocto
kirkstone
0.22.0
Exploitable
yocto
master
0.27.1
Not Affected