CVE-2025-13763

Published: April 3, 2026Last modified: April 6, 2026

Description

Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application crash. An attack requires a crafted USB device or smart card that would present the system with specially crafted responses to the APDUs

Severity score breakdown

ParameterValue
Base score5.7
Attack VectorPHYSICAL
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSopenscFixed (0.27.1-r0)
25 LTSopenscFixed (0.27.1-r0)
StreamopenscFixed (0.27.1-r0)

References

ON THIS PAGE