CVE-2019-16058: Opensc Project Opensc

High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.

An issue was discovered in the pam_p11 component 0.2.0 and 0.3.0 for OpenSC. If a smart card creates a signature with a length longer than 256 bytes, this triggers a buffer overflow. This may be the case for RSA keys with 4096 bits depending on the signature scheme.

Affected products

Published 2019-09-06. Last modified 2026-06-17.