CVE-2025-66038 is a memory corruption vulnerability (CWE-126) affecting OpenSC, an open-source smart card tool, in versions prior to 0.27.0. The flaw allows an attacker to provide untrusted compact-TLV data, causing the sc_compacttlv_find_tag function to return an out-of-bounds pointer due to insufficient length validation, leading to downstream memory corruption. Rated Medium severity (CVSS 6.8), it requires physical access (AV:P) but has low attack complexity (AC:L), potentially resulting in high impacts to confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, and its EPSS score is very low, indicating minimal current risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.27.0CPE matchmatch criteria | cpe:2.3:a:opensc_project:opensc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.