{"id":"CVE-2026-103531","summary":"OpenSC card-setcos.c setcos_construct_fci_44 stack-based overflow","details":"A flaw has been found in OpenSC up to 0.27.1. The impacted element is the function setcos_construct_fci_44 of the file src/libopensc/card-setcos.c. Executing a manipulation of the argument type_attr can lead to stack-based buffer overflow. The attack can be launched remotely. This patch is called ad730304052937c32b4eb489a06835ac6123632c. It is best practice to apply a patch to resolve this issue.","modified":"2026-10-02T08:13:50.101983Z","published":"2026-10-01T00:45:15.812Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-121"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103531.json"},"references":[{"type":"WEB","url":"https://github.com/OpenSC/OpenSC/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103531.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103531"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-103531"},{"type":"ADVISORY","url":"https://vuldb.com/submit/956910"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/412343"},{"type":"REPORT","url":"https://vuldb.com/vuln/412343/cti"},{"type":"FIX","url":"https://github.com/OpenSC/OpenSC/commit/ad730304052937c32b4eb489a06835ac6123632c"},{"type":"FIX","url":"https://github.com/OpenSC/OpenSC/pull/3812"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/opensc/opensc","events":[{"introduced":"aca07679a6dd281ee6411f5e7de2ed0ee796bee8"},{"fixed":"ad730304052937c32b4eb489a06835ac6123632c"}],"database_specific":{"extracted_events":[{"introduced":"0.27.0"},{"last_affected":"0.27.0"},{"introduced":"0.27.1"},{"last_affected":"0.27.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["0.27.0","0.27.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103531.json","vanir_signatures_modified":"2026-10-02T08:13:50Z","vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://github.com/opensc/opensc/commit/ad730304052937c32b4eb489a06835ac6123632c","target":{"file":"src/libopensc/card-setcos.c"},"deprecated":false,"digest":{"line_hashes":["188444882791401343814308368087227449773","255287473414578895801233644686997904169","199720571051964386185314939703604722375","262364367775997473953856059706205532802","167309018626210559516864418781908588900","56660642277665989202368885092511930793","206291762425855415636357188335520884140","168146349159072093215139798962742728625","265098098848641978286030226391255275832","309382543158221163977322538698882509383"],"threshold":0.9},"id":"CVE-2026-103531-6d03cb2f"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/opensc/opensc/commit/ad730304052937c32b4eb489a06835ac6123632c","target":{"file":"src/libopensc/card-setcos.c","function":"setcos_construct_fci_44"},"deprecated":false,"digest":{"function_hash":"294147007155743954127474483399428493291","length":2856},"id":"CVE-2026-103531-9217ea0f"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"}]}