Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Security update. Publication date: 18 Jun 2026 URL: https://advisories.mageia.org/MGASA-2026-0224.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-13763, CVE-2025-49010, CVE-2025-66037, CVE-2025-66038, CVE-2025-66215 Description: CVE-2025-66038 Memory corruption via improper compact-TLV length validation CVE-2025-66215 Stack-buffer-overflow with physical access via crafted smart card or USB device CVE-2025-49010 Stack-buffer-overflow via crafted smart card or USB device responses CVE-2025-66037 Out-of-bounds read via crafted input CVE-2025-13763 Several uses of potentially uninitialized memory detected by fuzzers References: - https://bugs.mageia.org/show_bug.cgi?id=35319 - https://lists.opensuse.org/archives/list/
New upstream release (#2442363) fixing various security issues.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-8c5856afbb 2026-04-25 01:21:36.171503+00:00 -------------------------------------------------------------------------------- Name : opensc Product : Fedora 44 Version : 0.27.1 Release : 1.fc44 URL : https://github.com/OpenSC/OpenSC/wiki Summary : Smart card library and applications Description : OpenSC provides a set of libraries and utilities to work with smart cards. Its main focus is on cards that support cryptographic operations, and facilitate their use in security applications such as authentication, mail encryption and digital signatures. OpenSC implements the PKCS#11 API so applications supporting this API (such as Mozilla Firefox and Thunderbird) can use it. On the card OpenSC implements the PKCS#15 standard and aims to be compatible with every software/card that does so, too. -------------------------------------------------------------------------------- Update Information: New upstream release (#2442363) fixing various security issues. -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 31 2026 Jakub Jelen - 0.27.1-1 - New upstream release (#2442363) fixing various security issues: - CVE-2025-66038 Memory corruption via improper compact-TLV length validation - CVE-2025-66215 Stack-buffer-overflow with physical access via crafted smart card or USB device - CVE-2025-49010 Stack-buffer-overflow via crafted smart card or USB device responses - CVE-2025-66037 Out-of-bounds read via crafted input - CVE-2025-13763 Several uses of potentially uninitialized memory detected by fuzzers -------------------------------------------------------------------------------- References: [ 1 ] Bug #2442363 - opensc-0.27.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2442363 [ 2 ]Bug #2453188 - CVE-2025-66037 opensc: OpenSC: Out-of-bounds read via crafted input [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453188 [ 3 ] Bug #2453189 - CVE-2025-49010 opensc: OpenSC: Stack-buffer-overflow via crafted smart card or USB device responses [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453189 [ 4 ] Bug #2453190 - CVE-2025-66215 opensc: OpenSC: Stack-buffer-overflow with physical access via crafted smart card or USB device [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453190 [ 5 ] Bug #2453191 - CVE-2025-66038 opensc: OpenSC: Memory corruption via improper compact-TLV length validation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453191 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-8c5856afbb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
New upstream release (#2442363) fixing various security issues:. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-4440b00e25 2026-04-09 03:21:08.450905+00:00 -------------------------------------------------------------------------------- Name : opensc Product : Fedora 43 Version : 0.27.1 Release : 1.fc43 URL : https://github.com/OpenSC/OpenSC/wiki Summary : Smart card library and applications Description : OpenSC provides a set of libraries and utilities to work with smart cards. Its main focus is on cards that support cryptographic operations, and facilitate their use in security applications such as authentication, mail encryption and digital signatures. OpenSC implements the PKCS#11 API so applications supporting this API (such as Mozilla Firefox and Thunderbird) can use it. On the card OpenSC implements the PKCS#15 standard and aims to be compatible with every software/card that does so, too. -------------------------------------------------------------------------------- Update Information: New upstream release (#2442363) fixing various security issues: -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 31 2026 Jakub Jelen - 0.27.1-1 - New upstream release (#2442363) fixing various security issues: - CVE-2025-66038 Memory corruption via improper compact-TLV length validation - CVE-2025-66215 Stack-buffer-overflow with physical access via crafted smart card or USB device - CVE-2025-49010 Stack-buffer-overflow via crafted smart card or USB device responses - CVE-2025-66037 Out-of-bounds read via crafted input - CVE-2025-13763 Several uses of potentially uninitialized memory detected by fuzzers -------------------------------------------------------------------------------- References: [ 1 ] Bug #2442363 - opensc-0.27.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2442363 [ 2 ]Bug #2453188 - CVE-2025-66037 opensc: OpenSC: Out-of-bounds read via crafted input [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453188 [ 3 ] Bug #2453189 - CVE-2025-49010 opensc: OpenSC: Stack-buffer-overflow via crafted smart card or USB device responses [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453189 [ 4 ] Bug #2453190 - CVE-2025-66215 opensc: OpenSC: Stack-buffer-overflow with physical access via crafted smart card or USB device [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453190 [ 5 ] Bug #2453191 - CVE-2025-66038 opensc: OpenSC: Memory corruption via improper compact-TLV length validation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453191 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-4440b00e25' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
New upstream release with security fixes for CVE-2023-5992 and CVE-2024-1454. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-3dbc3e8105 2024-03-23 00:20:56.399513 -------------------------------------------------------------------------------- Name : opensc Product : Fedora 40 Version : 0.25.0 Release : 1.fc40 URL : https://github.com/OpenSC/OpenSC/wiki Summary : Smart card library and applications Description : OpenSC provides a set of libraries and utilities to work with smart cards. Its main focus is on cards that support cryptographic operations, and facilitate their use in security applications such as authentication, mail encryption and digital signatures. OpenSC implements the PKCS#11 API so applications supporting this API (such as Mozilla Firefox and Thunderbird) can use it. On the card OpenSC implements the PKCS#15 standard and aims to be compatible with every software/card that does so, too. -------------------------------------------------------------------------------- Update Information: New upstream release with security fixes for CVE-2023-5992 and CVE-2024-1454 -------------------------------------------------------------------------------- ChangeLog: * Thu Mar 7 2024 Veronika Hanulikova - 0.25.0-1 - New upstream release (#2265003), fixes CVE-2023-5992 and CVE-2024-1454 (#2263930) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2263929 - CVE-2024-1454 opensc: Memory use after free in AuthentIC driver when updating token info https://bugzilla.redhat.com/show_bug.cgi?id=2263929 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-3dbc3e8105' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
New upstream release with security fixes for CVE-2023-5992 and CVE-2024-1454. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-b92d44f141 2024-03-16 01:50:49.900273 -------------------------------------------------------------------------------- Name : opensc Product : Fedora 38 Version : 0.25.0 Release : 1.fc38 URL : https://github.com/OpenSC/OpenSC/wiki Summary : Smart card library and applications Description : OpenSC provides a set of libraries and utilities to work with smart cards. Its main focus is on cards that support cryptographic operations, and facilitate their use in security applications such as authentication, mail encryption and digital signatures. OpenSC implements the PKCS#11 API so applications supporting this API (such as Mozilla Firefox and Thunderbird) can use it. On the card OpenSC implements the PKCS#15 standard and aims to be compatible with every software/card that does so, too. -------------------------------------------------------------------------------- Update Information: New upstream release with security fixes for CVE-2023-5992 and CVE-2024-1454 -------------------------------------------------------------------------------- ChangeLog: * Thu Mar 7 2024 Veronika Hanulikova - 0.25.0-1 - New upstream release (#2265003), fixes CVE-2023-5992 and CVE-2024-1454 (#2263930) * Sun Jan 21 2024 Fedora Release Engineering - 0.24.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2263929 - CVE-2024-1454 opensc: Memory use after free in AuthentIC driver when updating token info https://bugzilla.redhat.com/show_bug.cgi?id=2263929 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2024-b92d44f141' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
New upstream release (#2240701) with security fixes for CVE-2023-40660, CVE-2023-4535, CVE-2023-40661. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-c7e4c9af51 2023-12-23 04:33:53.210781 -------------------------------------------------------------------------------- Name : opensc Product : Fedora 38 Version : 0.24.0 Release : 1.fc38 URL : https://github.com/OpenSC/OpenSC/wiki Summary : Smart card library and applications Description : OpenSC provides a set of libraries and utilities to work with smart cards. Its main focus is on cards that support cryptographic operations, and facilitate their use in security applications such as authentication, mail encryption and digital signatures. OpenSC implements the PKCS#11 API so applications supporting this API (such as Mozilla Firefox and Thunderbird) can use it. On the card OpenSC implements the PKCS#15 standard and aims to be compatible with every software/card that does so, too. -------------------------------------------------------------------------------- Update Information: New upstream release (#2240701) with security fixes for CVE-2023-40660, CVE-2023-4535, CVE-2023-40661 -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 14 2023 Veronika Hanulikova - 0.24.0-1 - New upstream release (#2240701) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2240912 - CVE-2023-40660 OpenSC: Potential PIN bypass when card tracks its own login state https://bugzilla.redhat.com/show_bug.cgi?id=2240912 [ 2 ] Bug #2240913 - CVE-2023-40661 OpenSC: multiple memory issues with pkcs15-init (enrollment tool) https://bugzilla.redhat.com/show_bug.cgi?id=2240913 [ 3 ] Bug #2240914 - CVE-2023-4535 OpenSC: out-of-bounds read in MyEID driver handling encryption using symmetric keys https://bugzilla.redhat.com/show_bug.cgi?id=2240914 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-c7e4c9af51' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
A minor update fixing security problem within pkcs11-tool command. . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-4892 2009-05-12 23:51:52 -------------------------------------------------------------------------------- Name : opensc Product : Fedora 11 Version : 0.11.8 Release : 1.fc11 URL : Summary : Smart card library and applications Description : OpenSC is a package for for accessing smart card devices. Basic functionality (e.g. SELECT FILE, READ BINARY) should work on any ISO 7816-4 compatible smart card. Encryption and decryption using private keys on the smart card is possible with PKCS #15 compatible cards, such as the FINEID (Finnish Electronic IDentity) card. Swedish Posten eID cards have also been confirmed to work. -------------------------------------------------------------------------------- Update Information: A minor update fixing security problem within pkcs11-tool command. -------------------------------------------------------------------------------- ChangeLog: * Mon May 11 2009 Tomas Mraz - 0.11.8-1 - new upstream version - fixes security issue -------------------------------------------------------------------------------- References: [ 1 ] Bug #499862 - opensec: insecure public exponent in opensc 0.11.7 https://bugzilla.redhat.com/show_bug.cgi?id=499862 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update opensc' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
A minor update fixing security problem within pkcs11-tool command. . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-4883 2009-05-12 23:51:45 -------------------------------------------------------------------------------- Name : opensc Product : Fedora 9 Version : 0.11.8 Release : 1.fc9 URL : Summary : Smart card library and applications Description : OpenSC is a package for for accessing smart card devices. Basic functionality (e.g. SELECT FILE, READ BINARY) should work on any ISO 7816-4 compatible smart card. Encryption and decryption using private keys on the smart card is possible with PKCS #15 compatible cards, such as the FINEID (Finnish Electronic IDentity) card. Swedish Posten eID cards have also been confirmed to work. -------------------------------------------------------------------------------- Update Information: A minor update fixing security problem within pkcs11-tool command. -------------------------------------------------------------------------------- ChangeLog: * Mon May 11 2009 Tomas Mraz - 0.11.8-1 - new upstream version - fixes security issue * Fri Feb 27 2009 Tomas Mraz - 0.11.7-1 - new upstream version - fixes CVE-2009-0368 * Thu Feb 26 2009 Fedora Release Engineering - 0.11.6-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild * Thu Jan 15 2009 Tomas Mraz - 0.11.6-2 - Add explicit requires for pcsc-lite-libs. Dlopen libpcsclite with the full soname. * Tue Sep 2 2008 Tomas Mraz - 0.11.6-1 - Update to latest upstream, fixes CVE-2008-2235 * Thu Apr 10 2008 Hans de Goede - 0.11.4-5 - BuildRequire libassuan-devel instead of libassuan-static (bz 441812) -------------------------------------------------------------------------------- References: [ 1 ] Bug #499862 - opensec: insecure public exponent in opensc 0.11.7 https://bugzilla.redhat.com/show_bug.cgi?id=499862 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update opensc' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.