This update for opensc fixes the following issues:
- CVE-2025-49010: stack-buffer-overflow via crafted smart card or USB device responses (bsc#1261214).
- CVE-2025-66037: crafted input can cause an out-of-bounds read (bsc#1261218).
- CVE-2025-66038: improper compact-TLV length validation can lead to crash or unexpected behavior (bsc#1261219).
- CVE-2025-66215: crafted smart card or USB device can cause a stack-buffer-overflow write (bsc#1261220).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-932=1
- openSUSE Leap 16.0:
opensc-0.26.1-160000.3.1
opensc-bash-completion-0.26.1-160000.3.1
* bsc#1261214
* bsc#1261218
* bsc#1261219
* bsc#1261220
References:
* https://www.suse.com/security/cve/CVE-2025-49010.html
* https://www.suse.com/security/cve/CVE-2025-66037.html
* https://www.suse.com/security/cve/CVE-2025-66038.html
* https://www.suse.com/security/cve/CVE-2025-66215.html
Get the latest Linux and open source security news straight to your inbox.