CVE-2023-5992
published 2024-01-31CVE-2023-5992: A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the…
PriorityP430medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.16%
63.6th percentile
A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | opensc | < opensc 0.23.0-0.3+deb12u2 (bookworm) | opensc 0.23.0-0.3+deb12u2 (bookworm) |
| msrc | azl3_opensc_0.23.0-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_opensc_0.25.1-3_on_azure_linux_3.0 | — | — |
| msrc | cbl2_opensc_0.23.0-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_opensc_0.23.0-4_on_cbl_mariner_2.0 | — | — |
| opensc_project | opensc | < 0.25.0 | 0.25.0 |
| opensc_project | opensc | >= 0 < 0.21.0-1+deb11u1 | 0.21.0-1+deb11u1 |
| opensc_project | opensc | >= 0 < 0.23.0-0.3+deb12u2 | 0.23.0-0.3+deb12u2 |
| opensc_project | opensc | >= 0 < 0.25.0~rc1-1 | 0.25.0~rc1-1 |
| opensc_project | opensc | >= 0 < 0.25.0~rc1-1 | 0.25.0~rc1-1 |
| opensc_project | opensc | >= 0 < 0.15.0-1ubuntu1+esm3 | 0.15.0-1ubuntu1+esm3 |
| opensc_project | opensc | >= 0 < 0.15.0-1ubuntu1+esm2 | 0.15.0-1ubuntu1+esm2 |
| opensc_project | opensc | >= 0 < 0.17.0-3ubuntu0.1~esm3 | 0.17.0-3ubuntu0.1~esm3 |
| opensc_project | opensc | >= 0 < 0.17.0-3ubuntu0.1~esm2 | 0.17.0-3ubuntu0.1~esm2 |
| opensc_project | opensc | >= 0 < 0.20.0-3ubuntu0.1~esm3 | 0.20.0-3ubuntu0.1~esm3 |
| opensc_project | opensc | >= 0 < 0.20.0-3ubuntu0.1~esm4 | 0.20.0-3ubuntu0.1~esm4 |
| opensc_project | opensc | >= 0 < 0.20.0-3ubuntu0.1~esm2 | 0.20.0-3ubuntu0.1~esm2 |
| opensc_project | opensc | >= 0 < 0.22.0-1ubuntu2+esm1 | 0.22.0-1ubuntu2+esm1 |
| opensc_project | opensc | >= 0 < 0.25.0~rc1-1ubuntu0.1~esm1 | 0.25.0~rc1-1ubuntu0.1~esm1 |
| paloalto | pan-os | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_for_arm_64 | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv5.9MEDIUM
vendor_msrc5.9MEDIUM
vendor_debian5.6MEDIUM
vendor_redhat5.6MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
opensc vulnerabilities
osv·2025-04-09·CVSS 5.3
[MEDIUM] opensc vulnerabilities
opensc vulnerabilities
USN-7346-1 fixed vulnerabilities in OpenSC. The update introduced a
regression which broke smartcard based authentication. This update fixes
the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that OpenSC did not correctly handle certain memory
operations, which could lead to a use-after-free vulnerability. An
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-42780)
It was discovered that OpenSC did not correctly handle certain memory
operations, which could lead to a stack buffer overflow. An attacker
could possibly use this issue to cause a denial of service or execute
arbitrary code.
OSV
opensc regression
osv·2025-03-28·CVSS 5.3
[MEDIUM] opensc regression
opensc regression
USN-7346-1 fixed vulnerabilities in OpenSC. The update introduced a
regression in Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. The
security fix has been removed pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that OpenSC did not correctly handle certain memory
operations, which could lead to a use-after-free vulnerability. An
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-42780)
It was discovered that OpenSC did not correctly handle certain memory
operations, which could lead to a stack buffer overflow. An attacker
could possibly use this issue to cause
OSV
opensc vulnerabilities
osv·2025-03-12·CVSS 5.3
CVE-2021-42780 [MEDIUM] opensc vulnerabilities
opensc vulnerabilities
It was discovered that OpenSC did not correctly handle certain memory
operations, which could lead to a use-after-free vulnerability. An
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-42780)
It was discovered that OpenSC did not correctly handle certain memory
operations, which could lead to a stack buffer overflow. An attacker
could possibly use this issue to cause a denial of service or execute
arbitrary code. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-42782)
It was discovered that OpenSC did not correctly handle the length of
certain buffers, which could lead to a out-of-bounds access vulnerability.
An attacker co
OSV
CVE-2023-5992: A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant
osv·2024-01-31·CVSS 5.9
CVE-2023-5992 [MEDIUM] CVE-2023-5992: A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant
A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.
GHSA
GHSA-554m-v42f-hcq9: A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant
ghsa_unreviewed·2024-01-31
CVE-2023-5992 [MEDIUM] CWE-200 GHSA-554m-v42f-hcq9: A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant
A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.
Palo Alto
PAN-SA-2025-0010 Informational Bulletin: No Impact of the Marvin Attack on PAN-OS
vendor_paloalto·2025-05-14·CVSS 5.9
CVE-2024-29995 [MEDIUM] CWE-1240 PAN-SA-2025-0010 Informational Bulletin: No Impact of the Marvin Attack on PAN-OS
PAN-SA-2025-0010 Informational Bulletin: No Impact of the Marvin Attack on PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the applicability of CVEs related to the Marvin attack on PAN-OS. While we did not determine that any of these CVEs have significant impact on our PAN-OS software, some were fixed anyway out of an abundance of caution. You can also review more details about the Marvin attack if helpful. CVE Summary CVE-2024-29995 This CVE does not affect PAN-OS as PAN-OS does not have the vulnerable opensc library. CVE-2024-26306 This CVE does not affect PAN-OS as PAN-OS does not have the vulnerable iperf3 component. CVE-2024-23170 This CVE does not affect PAN-OS as PAN-OS does not have the vulnerable Mbed TLS component. CVE-2024-21484 This CVE does not aff
Ubuntu
OpenSC vulnerabilities
vendor_ubuntu·2025-04-09·CVSS 5.3
CVE-2021-42780 [MEDIUM] OpenSC vulnerabilities
Title: OpenSC vulnerabilities
Summary: USN-7346-1 introduced a regression in OpenSC.
USN-7346-1 fixed vulnerabilities in OpenSC. The update introduced a
regression which broke smartcard based authentication. This update fixes
the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that OpenSC did not correctly handle certain memory
operations, which could lead to a use-after-free vulnerability. An
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-42780)
It was discovered that OpenSC did not correctly handle certain memory
operations, which could lead to a stack buffer overflow. An attacker
could possibly use thi
Ubuntu
OpenSC regression
vendor_ubuntu·2025-03-28·CVSS 5.3
[MEDIUM] OpenSC regression
Title: OpenSC regression
Summary: USN-7346-1 introduced a regression in OpenSC.
USN-7346-1 fixed vulnerabilities in OpenSC. The update introduced a
regression in Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. The
security fix has been removed pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that OpenSC did not correctly handle certain memory
operations, which could lead to a use-after-free vulnerability. An
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-42780)
It was discovered that OpenSC did not correctly handle certain memory
operations, which could lead to a stack buffe
Ubuntu
OpenSC vulnerabilities
vendor_ubuntu·2025-03-12·CVSS 5.3
CVE-2021-42780 [MEDIUM] OpenSC vulnerabilities
Title: OpenSC vulnerabilities
Summary: Several security issues were fixed in opensc.
It was discovered that OpenSC did not correctly handle certain memory
operations, which could lead to a use-after-free vulnerability. An
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-42780)
It was discovered that OpenSC did not correctly handle certain memory
operations, which could lead to a stack buffer overflow. An attacker
could possibly use this issue to cause a denial of service or execute
arbitrary code. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-42782)
It was discovered that OpenSC did not correctly handle the length of
certain buffers, which cou
Microsoft
Opensc: side-channel leaks while stripping encryption pkcs#1 padding
vendor_msrc·2024-01-09·CVSS 5.9
CVE-2023-5992 [MEDIUM] CWE-203 Opensc: side-channel leaks while stripping encryption pkcs#1 padding
Opensc: side-channel leaks while stripping encryption pkcs#1 padding
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference
Red Hat
OpenSC: Side-channel leaks while stripping encryption PKCS#1 padding
vendor_redhat·2023-11-28·CVSS 5.6
CVE-2023-5992 [MEDIUM] CWE-203 OpenSC: Side-channel leaks while stripping encryption PKCS#1 padding
OpenSC: Side-channel leaks while stripping encryption PKCS#1 padding
A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.
A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.
Package: opensc (Red Hat Enterprise Linux 7) - Affected
Debian
CVE-2023-5992: opensc - A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is n...
vendor_debian·2023·CVSS 5.6
CVE-2023-5992 [MEDIUM] CVE-2023-5992: opensc - A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is n...
A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.
Scope: local
bookworm: resolved (fixed in 0.23.0-0.3+deb12u2)
bullseye: resolved (fixed in 0.21.0-1+deb11u1)
forky: resolved (fixed in 0.25.0~rc1-1)
sid: resolved (fixed in 0.25.0~rc1-1)
trixie: resolved (fixed in 0.25.0~rc1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2024:0966https://access.redhat.com/errata/RHSA-2024:0967https://access.redhat.com/security/cve/CVE-2023-5992https://bugzilla.redhat.com/show_bug.cgi?id=2248685https://github.com/OpenSC/OpenSC/wiki/CVE-2023-5992https://www.usenix.org/system/files/usenixsecurity24-shagam.pdfhttps://access.redhat.com/errata/RHSA-2024:0966https://access.redhat.com/errata/RHSA-2024:0967https://access.redhat.com/security/cve/CVE-2023-5992https://bugzilla.redhat.com/show_bug.cgi?id=2248685https://github.com/OpenSC/OpenSC/wiki/CVE-2023-5992https://lists.debian.org/debian-lts-announce/2024/12/msg00026.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/OWIZ5ZLO5ECYPLSTESCF7I7PQO5X6ZSU/https://lists.fedoraproject.org/archives/list/[email protected]/message/RJI2FWLY24EOPALQ43YPQEZMEP3APPPI/https://lists.fedoraproject.org/archives/list/[email protected]/message/UECKC7X4IM4YZQ5KRQMNBNKNOXLZC7RZ/
2024-01-31
Published