Description:
CVE-2025-66038 Memory corruption via improper compact-TLV length
validation
CVE-2025-66215 Stack-buffer-overflow with physical access via crafted
smart card or USB device
CVE-2025-49010 Stack-buffer-overflow via crafted smart card or USB
device responses
CVE-2025-66037 Out-of-bounds read via crafted input
CVE-2025-13763 Several uses of potentially uninitialized memory detected
by fuzzers
- https://bugs.mageia.org/show_bug.cgi?id=35319
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/3VEH2KIGJ2SHJ7FWKNUDZSA2JUHQFRZS/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2WSLOFM35Z6Y4PLTNF7MFB4JO2WJAIMX/
- https://www.cve.org/CVERecord?id=CVE-2025-13763
- https://www.cve.org/CVERecord?id=CVE-2025-49010
- https://www.cve.org/CVERecord?id=CVE-2025-66037
- https://www.cve.org/CVERecord?id=CVE-2025-66038
- https://www.cve.org/CVERecord?id=CVE-2025-66215
- 9/core/opensc-0.25.0-1.2.mga9
Publication date:18 Jun 2026
Get the latest Linux and open source security news straight to your inbox.