CVE-2026-10275

A flaw has been found in OpenSC up to 0.26.1. This affects the function test_kpgen_certwrite of the file src/tools/pkcs11-tool.c of the component pkcs11-tool Key Generation Module. This manipulation causes buffer overflow. The attack is possible to be carried out remotely. The complexity of an attack is rather high. It is indicated that the exploitability is difficult. The exploit has been published and may be used. Patch name: 814f745b3b6d100295f65f1935edd33d520d33ab. It is recommended to apply a patch to fix this issue.
Configurations

No configuration.

History

22 Jul 2026, 07:10

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad en OpenSC hasta la versión 0.26.1. Esto afecta a la función test_kpgen_certwrite del archivo src/tools/pkcs11-tool.c del componente pkcs11-tool Key Generation Module. Esta manipulación provoca desbordamiento de búfer. El ataque puede llevarse a cabo de forma remota. La complejidad de un ataque es bastante alta. Se indica que la explotabilidad es difícil. El exploit ha sido publicado y puede ser utilizado. Nombre del parche: 814f745b3b6d100295f65f1935edd33d520d33ab. Se recomienda aplicar un parche para corregir este problema.

01 Jun 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-01 17:16

Updated : 2026-07-22 07:10


NVD link : CVE-2026-10275

Mitre link : CVE-2026-10275

CVE.ORG link : CVE-2026-10275


JSON object : View

Products Affected

No product.

CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')