CVE-2025-66215
published 2026-03-30CVE-2025-66215: OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or…
PriorityP431medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
EPSS
0.16%
5.5th percentile
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow WRITE in card-oberthur. The attack requires crafted USB device or smart card that would present the system with specially crafted responses to the APDUs. This issue has been patched in version 0.27.0.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | opensc | < opensc 0.27.0~rc1-1 (forky) | opensc 0.27.0~rc1-1 (forky) |
| opensc | opensc | < 0.27.0 | 0.27.0 |
| opensc_project | opensc | < 0.27.0 | 0.27.0 |
| opensc_project | opensc | >= 0 < 0.27.0~rc1-1 | 0.27.0~rc1-1 |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv6.8MEDIUM
vendor_debian3.8LOW
vendor_redhat3.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
OpenSC: OpenSC: Stack-buffer-overflow with physical access via crafted smart card or USB device
vendor_redhat·2026-03-30·CVSS 3.8
CVE-2025-66215 [LOW] CWE-120 OpenSC: OpenSC: Stack-buffer-overflow with physical access via crafted smart card or USB device
OpenSC: OpenSC: Stack-buffer-overflow with physical access via crafted smart card or USB device
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow WRITE in card-oberthur. The attack requires crafted USB device or smart card that would present the system with specially crafted responses to the APDUs. This issue has been patched in version 0.27.0.
A flaw was found in OpenSC, an open-source smart card tool and middleware. An attacker with physical access to the computer can exploit this vulnerability when a user or administrator uses a smart card token. By presenting a specially crafted USB device or smart card, the attacker can tr
Debian
CVE-2025-66215: opensc - OpenSC is an open source smart card tools and middleware. Prior to version 0.27....
vendor_debian·2025·CVSS 3.8
CVE-2025-66215 [LOW] CVE-2025-66215: opensc - OpenSC is an open source smart card tools and middleware. Prior to version 0.27....
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow WRITE in card-oberthur. The attack requires crafted USB device or smart card that would present the system with specially crafted responses to the APDUs. This issue has been patched in version 0.27.0.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 0.27.0~rc1-1)
sid: resolved (fixed in 0.27.0~rc1-1)
trixie: open
OSV
CVE-2025-66215: OpenSC is an open source smart card tools and middleware
osv·2026-03-30·CVSS 6.8
CVE-2025-66215 [MEDIUM] CVE-2025-66215: OpenSC is an open source smart card tools and middleware
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow WRITE in card-oberthur. The attack requires crafted USB device or smart card that would present the system with specially crafted responses to the APDUs. This issue has been patched in version 0.27.0.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-66215 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.8
CVE-2025-66215 [LOW] CVE-2025-66215 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66215 :
NixOS vulnerability analysis and mitigation
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow WRITE in card-oberthur. The attack requires crafted USB device or smart card that would present the system with specially crafted responses to the APDUs. This issue has been patched in version 0.27.0.
Source : NVD
## 6.8
Score
Published March 30, 2026
Severity MEDIUM
CNA Score 3.8
Affected Technologies
NixOS
Homebrew
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.8
Exploitation Probability (EPSS) N/A
Affecte
Bugzilla
CVE-2025-66215 OpenSC: OpenSC: Stack-buffer-overflow with physical access via crafted smart card or USB device
bugzilla·2026-03-30·CVSS 6.8
CVE-2025-66215 [MEDIUM] CVE-2025-66215 OpenSC: OpenSC: Stack-buffer-overflow with physical access via crafted smart card or USB device
CVE-2025-66215 OpenSC: OpenSC: Stack-buffer-overflow with physical access via crafted smart card or USB device
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow WRITE in card-oberthur. The attack requires crafted USB device or smart card that would present the system with specially crafted responses to the APDUs. This issue has been patched in version 0.27.0.
Bugzilla
CVE-2025-66215 opensc: OpenSC: Stack-buffer-overflow with physical access via crafted smart card or USB device [fedora-all]
bugzilla·2026-03-30·CVSS 3.8
CVE-2025-66215 [LOW] CVE-2025-66215 opensc: OpenSC: Stack-buffer-overflow with physical access via crafted smart card or USB device [fedora-all]
CVE-2025-66215 opensc: OpenSC: Stack-buffer-overflow with physical access via crafted smart card or USB device [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-8c5856afbb (opensc-0.27.1-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-8c5856afbb
---
FEDORA-2026-4440b00e25 (opensc-0.27.1-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-4440b00e25
---
FEDORA-2026-4440b00e25 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the upda
2026-03-30
Published