HomeDefectsLIN1022-5547
Fixed

LIN1022-5547 : Security Advisory - opensc - CVE-2023-40661

Created: Oct 6, 2023    Updated: Mar 7, 2025
Resolved Date: Oct 8, 2024
Found In Version: 10.22.33.1
Fix Version: 10.22.33.19
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Userspace

Description

Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user or administrator enrolls cards. To take advantage of these flaws, an attacker must have physical access to the computer system and employ a custom-crafted USB device or smart card to manipulate responses to APDUs. This manipulation can potentially allow 
compromise key generation, certificate loading, and other card management operations during enrollment.

https://nvd.nist.gov/vuln/detail/CVE-2023-40661

CVEs