CVE-2017-6414: Libcacard Project Libcacard
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Memory leak in the vcard_apdu_new function in card_7816.c in libcacard before 2.5.3 allows local guest OS users to cause a denial of service (host memory consumption) via vectors related to allocating a new APDU object.
Affected products
- Libcacard Project Libcacard: before 2.5.3 (fixed in 2.5.3)
Published 2017-03-15. Last modified 2026-06-17.