{"id":"AZL-89150","summary":"CVE-2026-40510 affecting package opensc for versions less than 0.27.0-rc1","details":"OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device returning a URL field longer than 118 bytes in the Key History Object ASN.1 response.","modified":"2026-08-30T05:26:50Z","published":"2026-05-29T14:16:26Z","upstream":["CVE-2026-40510"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40510"}],"affected":[{"package":{"name":"opensc","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/opensc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.27.0-rc1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-89150.json"}}],"schema_version":"1.9.0"}