{"id":"CLSA-2026-1779190223","summary":"opensc: Fix of 5 CVEs","details":"- CVE-2023-5992: implement constant-time PKCS#1 v1.5 depadding to prevent Bleichenbacher/Marvin-style timing attacks\n- CVE-2025-49010: fix stack buffer overflow write in iso7816 GET RESPONSE\n- CVE-2025-66037: fix out-of-bounds heap read in sc_pkcs15_pubkey_from_spki_fields\n- CVE-2025-66038: fix buffer over-read in sc_compacttlv_find_tag\n- CVE-2025-66215: fix stack buffer overflow write in card-oberthur auth_compute_signature and auth_read_record","modified":"2026-05-27T11:17:52.168991934Z","published":"2026-05-19T11:30:52Z","upstream":["CVE-2023-5992","CVE-2025-49010","CVE-2025-66037","CVE-2025-66038","CVE-2025-66215"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/almalinux9.2esu/CLSA-2026-1779190223.html"}],"affected":[{"package":{"name":"opensc","ecosystem":"TuxCare:AlmaLinux:9.2","purl":"pkg:rpm/tuxcare/opensc?distro=almalinux-9.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.22.0-2.el9_2.tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1779190223.json"}}],"schema_version":"1.7.5"}