Debian Patches

Status for opensc/0.27.1-3

Patch Description Author Forwarded Bugs Origin Last update
0001-Use-sysconfdir-opensc-for-opensc.conf.patch Use $sysconfdir/opensc for opensc.conf Eric Dorland <eric@debian.org> no 2020-01-26
0002-Drop-non-functional-ENABLE_AUTOSTART.patch Drop non-functional ENABLE_AUTOSTART Bastian Germann <bage@debian.org> no 2023-11-10
CVE-2026-10275.patch pkcs11-tool: prevent buffer overflow
Reported by @HMF2021 hippofu999
Frank Morgner <frankmorgner@gmail.com> no upstream, 814f745b3b6d100295f65f1935edd33d520d33ab 2026-05-11
CVE-2026-103531.patch setcos: Fix buffer overflow in setcos_construct_fci_44
The FCI construction copied type_attr, sec_attr and prop_attr of the
file into a fixed 64-byte stack buffer without checking the length.
Malicious or corrupted attribute lengths (e.g. prop_attr_len > 64,
reachable through fuzz_pkcs15init and attacker-controlled card
responses) caused a stack buffer overflow (write).

Return SC_ERROR_INVALID_DATA if any attribute exceeds the buffer size.

Found with the fuzz_pkcs15init fuzzer.
wanglanlan <wanglanlan@users.noreply.github.com> no upstream, ad730304052937c32b4eb489a06835ac6123632c 2026-09-02

All known versions for source package 'opensc'

Links