CVE-2025-13763: Opensc

Medium severity, CVSS 5.7. EPSS: 0.2% chance of exploitation in the next 30 days.

Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application crash. An attack requires a crafted USB device or smart card that would present the system with specially crafted responses to the APDUs

Affected products

  • Opensc Opensc: before 0.27.0 (fixed in 0.27.0)
  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9

Published 2026-04-23. Last modified 2026-06-30.