CVE-2016-10109: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 4% chance of exploitation in the next 30 days.
Use-after-free vulnerability in pcsc-lite before 1.8.20 allows a remote attackers to cause denial of service (crash) via a command that uses "cardsList" after the handle has been released through the SCardReleaseContext function.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 16.10 only
- Muscle Pcsc-Lite: up to and including 1.8.19
Published 2017-02-23. Last modified 2026-06-17.