#1149970 opensc: CVE-2026-103531

Package:
src:opensc
Source:
src:opensc
Submitter:
Salvatore Bonaccorso
Date:
2026-10-04 20:45:03 UTC
Severity:
normal
Tags:
#1149970#5
Date:
2026-10-04 19:57:20 UTC
From:
To:
Hi,

The following vulnerability was published for opensc.

CVE-2026-103531[0]:
| A flaw has been found in OpenSC up to 0.27.1. The impacted element
| is the function setcos_construct_fci_44 of the file
| src/libopensc/card-setcos.c. Executing a manipulation of the
| argument type_attr can lead to stack-based buffer overflow. The
| attack can be launched remotely. This patch is called
| ad730304052937c32b4eb489a06835ac6123632c. It is best practice to
| apply a patch to resolve this issue.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-103531
https://www.cve.org/CVERecord?id=CVE-2026-103531
[1] https://github.com/OpenSC/OpenSC/pull/3812

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1149970#8
Date:
2026-10-04 20:17:18 UTC
From:
To:
Hello,

Bug #1149970 in opensc reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/opensc-team/opensc/-/commit/87564a1abfd8ee594ccaf9779f8d144ccafae661

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149970

#1149970#15
Date:
2026-10-04 20:44:21 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
opensc, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1149970@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Bastian Germann <bage@debian.org> (supplier of updated opensc package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 04 Oct 2026 22:16:07 +0200
Source: opensc
Architecture: source
Version: 0.27.1-3
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenSC Maintainers <pkg-opensc-maint@lists.alioth.debian.org>
Changed-By: Bastian Germann <bage@debian.org>
Closes: 1149970
Changes:
 opensc (0.27.1-3) unstable; urgency=medium
 .
   * Team upload
   * Add upstream fix for CVE-2026-103531 (Closes: #1149970)
 .
   [ Vilius Panevėžys ]
   * Drop retired alternative names of Mozilla projects
Checksums-Sha1:
 04ccf32beffd9716fa5f519fce756a79a99b61e6 2007 opensc_0.27.1-3.dsc
 2d978177475dc21a4e71153e9f20c27cadef88c8 16544 opensc_0.27.1-3.debian.tar.xz
 2ec055694dc461fbe5cd969c57f745323210eedc 6940 opensc_0.27.1-3_source.buildinfo
Checksums-Sha256:
 1c0642ee2af3ab96dd0c046f71862b2a9f3515457749a71fe032921a9c05f08e 2007 opensc_0.27.1-3.dsc
 e92e0b858ee49c66675532cd679dfa4ddb2c6ecd0d920f168e0de81f4d2d82d5 16544 opensc_0.27.1-3.debian.tar.xz
 b18d74f0d9b8988aea921e3b6bbe4ca5592183f29344055bf58d4c2c545c19d1 6940 opensc_0.27.1-3_source.buildinfo
Files:
 68043ba3133c2046e2af3d731d7dcdd3 2007 utils optional opensc_0.27.1-3.dsc
 6189474b685bbb69de65c07919cfd886 16544 utils optional opensc_0.27.1-3.debian.tar.xz
 f3047338e7e4ed73b9a3aee9f867fbcf 6940 utils optional opensc_0.27.1-3_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQHEBAEBCgAuFiEEQGIgyLhVKAI3jM5BH1x6i0VWQxQFAmrCtFgQHGJhZ2VAZGVi
aWFuLm9yZwAKCRAfXHqLRVZDFJs9C/95ssvVaY5FueRhmpYz4JoI2SJj0KSr/WaH
hcyoL4AvolYrqMYo6ahg2bIKJzcCpqM1Xnh05LzmVgJVdX25qUq7xtUjneqwACdR
t84oEItDX9OvhJqcIMkY1GSK8W1SSb2TNfdVry0R/FKG2WcB1m6lvE3dMyLo+dpC
BfLPTh8/vQ1Qg5fapAZobZshj0++evfwc/LlxgtKJ+lWdlruWS5FUYhwHwBgvX/b
AWEybqDMwkFP9We0CKYUONvgaCZWyOAtxo5e1iChGdThInshlxO1En9UM99lTugR
uAovXODv5bwrvNfPfmlGm2qmJC8OyKtLCdxmz6+JpfiP7E9TLg3ddfhyRTacfBl7
UX3bdGwBjlwoqN4kpzcMjdTepG+ObU0HrUgpeOhmpHciywzMpfUeO3aTQN/pJUAQ
eLMH6brIPbfJozGnDaBfvZ/UOV+MSe9T71ZItE5xEhS5pWAo0/FOr+y+SShAz25s
uK2U6et9e0rlsUCIAY5zAsewvAzcONI=
=UAxl
-----END PGP SIGNATURE-----