CVE-2025-49010
published 2026-03-30CVE-2025-49010: OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or…
PriorityP431medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
EPSS
0.13%
3.0th percentile
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow write in GET RESPONSE. The attack requires crafted USB device or smart card that would present the system with specially crafted responses to the APDUs. This issue has been patched in version 0.27.0.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | opensc | < opensc 0.27.0~rc1-1 (forky) | opensc 0.27.0~rc1-1 (forky) |
| opensc | opensc | < 0.27.0 | 0.27.0 |
| opensc_project | opensc | < 0.27.0 | 0.27.0 |
| opensc_project | opensc | >= 0 < 0.27.0~rc1-1 | 0.27.0~rc1-1 |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv6.8MEDIUM
vendor_debian3.8LOW
vendor_redhat3.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
OpenSC: OpenSC: Stack-buffer-overflow via crafted smart card or USB device responses
vendor_redhat·2026-03-30·CVSS 3.8
CVE-2025-49010 [LOW] CWE-120 OpenSC: OpenSC: Stack-buffer-overflow via crafted smart card or USB device responses
OpenSC: OpenSC: Stack-buffer-overflow via crafted smart card or USB device responses
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow write in GET RESPONSE. The attack requires crafted USB device or smart card that would present the system with specially crafted responses to the APDUs. This issue has been patched in version 0.27.0.
A flaw was found in OpenSC, an open source smart card tools and middleware. An attacker with physical access to the computer, at the time a user or administrator uses a token, can exploit this vulnerability. By presenting specially crafted responses to Application Protocol Data Units (APDUs) from a
Debian
CVE-2025-49010: opensc - OpenSC is an open source smart card tools and middleware. Prior to version 0.27....
vendor_debian·2025·CVSS 3.8
CVE-2025-49010 [LOW] CVE-2025-49010: opensc - OpenSC is an open source smart card tools and middleware. Prior to version 0.27....
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow write in GET RESPONSE. The attack requires crafted USB device or smart card that would present the system with specially crafted responses to the APDUs. This issue has been patched in version 0.27.0.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 0.27.0~rc1-1)
sid: resolved (fixed in 0.27.0~rc1-1)
trixie: open
OSV
CVE-2025-49010: OpenSC is an open source smart card tools and middleware
osv·2026-03-30·CVSS 6.8
CVE-2025-49010 [MEDIUM] CVE-2025-49010: OpenSC is an open source smart card tools and middleware
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow write in GET RESPONSE. The attack requires crafted USB device or smart card that would present the system with specially crafted responses to the APDUs. This issue has been patched in version 0.27.0.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-49010 opensc: OpenSC: Stack-buffer-overflow via crafted smart card or USB device responses [fedora-all]
bugzilla·2026-03-30·CVSS 3.8
CVE-2025-49010 [LOW] CVE-2025-49010 opensc: OpenSC: Stack-buffer-overflow via crafted smart card or USB device responses [fedora-all]
CVE-2025-49010 opensc: OpenSC: Stack-buffer-overflow via crafted smart card or USB device responses [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-8c5856afbb (opensc-0.27.1-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-8c5856afbb
---
FEDORA-2026-4440b00e25 (opensc-0.27.1-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-4440b00e25
---
FEDORA-2026-4440b00e25 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the
Bugzilla
CVE-2025-49010 OpenSC: OpenSC: Stack-buffer-overflow via crafted smart card or USB device responses
bugzilla·2026-03-30·CVSS 6.8
CVE-2025-49010 [MEDIUM] CVE-2025-49010 OpenSC: OpenSC: Stack-buffer-overflow via crafted smart card or USB device responses
CVE-2025-49010 OpenSC: OpenSC: Stack-buffer-overflow via crafted smart card or USB device responses
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow write in GET RESPONSE. The attack requires crafted USB device or smart card that would present the system with specially crafted responses to the APDUs. This issue has been patched in version 0.27.0.
Wiz
CVE-2025-49010 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.8
CVE-2025-49010 [LOW] CVE-2025-49010 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-49010 :
NixOS vulnerability analysis and mitigation
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow write in GET RESPONSE. The attack requires crafted USB device or smart card that would present the system with specially crafted responses to the APDUs. This issue has been patched in version 0.27.0.
Source : NVD
## 6.8
Score
Published March 30, 2026
Severity MEDIUM
CNA Score 3.8
Affected Technologies
NixOS
Homebrew
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4
Exploitation Probability (EPSS) N/A
Affected p
2026-03-30
Published