[CLSA-2026:1787393949] opensc: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-08-22 10:19:20 UTC
Description:
- CVE-2024-8443: fix heap buffer overflow in the OpenPGP driver when writing the key fingerprint, reject key responses not matching the requested algorithm and set the EC point length from the received response - CVE-2026-10275: fix buffer overflow in pkcs11-tool when copying a token supplied CKA_ID into the object id buffer
Updated packages:
  • opensc-0.23.0-5.el9.tuxcare.els6.i686.rpm
    sha:1052beba0630f974a5e1b6667596a4f46fd0b913f0b9d1435af2ce210cab9034
  • opensc-0.23.0-5.el9.tuxcare.els6.x86_64.rpm
    sha:153b70a0d01466468353aa6f4a48df114ab0b74b19014a8f19860d2537d99a45
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.