CVE-2025-13763
published 2026-04-23CVE-2025-13763: Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application crash. An attack requires a crafted USB…
PriorityP423medium5.7CVSS 3.1
AVPACHPRNUINSUCHINAH
EPSS
0.18%
7.3th percentile
Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application crash. An attack requires a crafted USB device or smart card that would present the system with specially crafted responses to the APDUs
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | opensc | < opensc 0.27.0~rc1-1 (forky) | opensc 0.27.0~rc1-1 (forky) |
| opensc | opensc | < 0.27.0 | 0.27.0 |
| opensc_project | opensc | — | — |
CVSS provenance
nvdv3.15.7MEDIUMCVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
vendor_redhat5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libopensc: opensc: Multiple uses of uninitialized variable
vendor_redhat·2026-04-23·CVSS 5.7
CVE-2025-13763 [MEDIUM] libopensc: opensc: Multiple uses of uninitialized variable
libopensc: opensc: Multiple uses of uninitialized variable
Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application crash. An attack requires a crafted USB device or smart card that would present the system with specially crafted responses to the APDUs
Statement: Physical access is required for a successful attack of this vulnerability which increases the complexity and lowers the severity of this flaw hence it was rated Low.
Mitigation: To mitigate this issue, avoid connecting untrusted USB devices or smart cards to systems running affected versions of Red Hat Enterprise Linux. This operational control reduces the risk of an attacker presenting a specially crafted device to exploit the uninitialized variable flaws in `libop
Debian
CVE-2025-13763: opensc
vendor_debian·2025
CVE-2025-13763 CVE-2025-13763: opensc
bookworm: open
bullseye: open
forky: resolved (fixed in 0.27.0~rc1-1)
sid: resolved (fixed in 0.27.0~rc1-1)
trixie: open
VulDB
libopensc up to 0.26.x USB Device uninitialized pointer (EUVD-2025-209564)
vuldb·2026-04-23·CVSS 5.7
CVE-2025-13763 [MEDIUM] libopensc up to 0.26.x USB Device uninitialized pointer (EUVD-2025-209564)
A vulnerability marked as problematic has been reported in libopensc up to 0.26.x. Affected by this vulnerability is an unknown functionality of the component USB Device Handler. Performing a manipulation results in uninitialized pointer.
This vulnerability is cataloged as CVE-2025-13763. The attack may be carried out on the physical device. There is no exploit available.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-13763 opensc: Multiple uses of uninitialized variable [fedora-43]
bugzilla·2026-04-23·CVSS 5.7
CVE-2025-13763 [MEDIUM] CVE-2025-13763 opensc: Multiple uses of uninitialized variable [fedora-43]
CVE-2025-13763 opensc: Multiple uses of uninitialized variable [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This was fixed with opensc-0.27.1-1.fc43:
https://bodhi.fedoraproject.org/updates/FEDORA-2026-4440b00e25
Bugzilla
CVE-2025-13763 opensc: Multiple uses of uninitialized variable [fedora-42]
bugzilla·2026-04-23·CVSS 5.7
CVE-2025-13763 [MEDIUM] CVE-2025-13763 opensc: Multiple uses of uninitialized variable [fedora-42]
CVE-2025-13763 opensc: Multiple uses of uninitialized variable [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This was fixed with opensc-0.27.1-1.fc42:
https://bodhi.fedoraproject.org/updates/FEDORA-2026-de85b06438
Bugzilla
CVE-2025-13763 libopensc: opensc: Multiple uses of uninitialized variable
bugzilla·2025-11-27·CVSS 5.7
CVE-2025-13763 [MEDIUM] CVE-2025-13763 libopensc: opensc: Multiple uses of uninitialized variable
CVE-2025-13763 libopensc: opensc: Multiple uses of uninitialized variable
Multiple issues with uninitialized variables were found in libopensc that may lead to information disclosure or application crash. An attack requires a crafted USB device or smart card that would present the system with specially crafted responses to the APDUs
https://access.redhat.com/security/cve/CVE-2025-13763https://bugzilla.redhat.com/show_bug.cgi?id=2417581https://github.com/OpenSC/OpenSC/security/advisories/GHSA-2v44-fq35-98vvhttps://github.com/OpenSC/OpenSC/wiki/CVE-2025-13763https://github.com/OpenSC/OpenSC/security/advisories/GHSA-2v44-fq35-98vv
2026-04-23
Published