{"id":"CVE-2026-40528","summary":"OpenSC \u003c 0.27.0 Buffer Overrun in do_key_value() via profile.c","details":"OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init/profile.c that allows attackers to corrupt memory by supplying a crafted profile configuration file. During pkcs15-init invocation, a key value entry beginning with '=' followed by more than sizeof(keybuf) characters is copied into keybuf via memcpy without a length check, causing both stack and heap buffer overruns.","modified":"2026-08-05T03:32:33.970986887Z","published":"2026-05-29T13:38:11.831Z","related":["SUSE-SU-2026:22103-1","SUSE-SU-2026:22139-1","SUSE-SU-2026:2657-1","SUSE-SU-2026:2697-1","openSUSE-SU-2026:11022-1"],"database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-121","CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40528.json","unresolved_ranges":[{"extracted_events":[{"fixed":"0.27.0"},{"fixed":"0358817ec74aeca654f83e7709c7720b14c5db59"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"fixed":"0.27.0"}],"source":"CPE_FIELD"},{"extracted_events":[{"fixed":"0.27.0"}],"source":"DESCRIPTION"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40528.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40528"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/opensc-buffer-overrun-in-do-key-value-via-profile-c"},{"type":"FIX","url":"https://github.com/OpenSC/OpenSC/commit/0358817ec74aeca654f83e7709c7720b14c5db59"},{"type":"PACKAGE","url":"https://github.com/OpenSC/OpenSC"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/opensc/opensc","events":[{"introduced":"0"},{"fixed":"0358817ec74aeca654f83e7709c7720b14c5db59"}],"database_specific":{"source":"REFERENCES"}}],"versions":["0.27.0-rc2","tag-test","0.27.0-rc1","0.26.0","0.26.0-rc1","0.25.0","0.25.0-rc1","0.24.0","0.24.0-rc2","0.24.0-rc1","0.23.0","0.23.0-rc2","0.23.0-rc1","0.22.0","0.22.0-rc2","0.22.0-rc1","0.21.0","0.21.0-rc2","0.21.0-rc1","0.20.0","0.20.0-rc4","0.20.0-rc3","0.20.0-rc2","0.20.0-rc1","0.19.0","0.19.0-rc1","0.18.0","0.18.0-rc2","0.18.0-rc1","0.17.0","0.17.0-rc2","0.17.0-rc1","0.16.0","v0.16.0-pre1","0.15.0","0.14.0","0.14.0rtm","0.14.0rc2","0.13.0","0.13.0rc1","0.13.0pre1","v0.12.2","0.12.2","0.12.2-rc1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40528.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}]}