No advisories yet.
Solution
No solution given by the vendor.
Workaround
To mitigate this issue, avoid connecting untrusted USB devices or smart cards to systems running affected versions of Red Hat Enterprise Linux. This operational control reduces the risk of an attacker presenting a specially crafted device to exploit the uninitialized variable flaws in `libopensc`.
Thu, 23 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-457 | |
| Metrics |
ssvc
|
Thu, 23 Apr 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application crash. An attack requires a crafted USB device or smart card that would present the system with specially crafted responses to the APDUs | |
| Title | Libopensc: opensc: multiple uses of uninitialized variable | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-04-23T14:05:23.182Z
Reserved: 2025-11-27T14:35:05.731Z
Link: CVE-2025-13763
Updated: 2026-04-23T14:05:19.606Z
Status : Received
Published: 2026-04-23T13:16:09.697
Modified: 2026-04-23T13:16:09.697
Link: CVE-2025-13763
No data.
OpenCVE Enrichment
No data.