{
  "threat_severity" : "Low",
  "public_date" : "2026-04-23T12:09:46Z",
  "bugzilla" : {
    "description" : "libopensc: opensc: Multiple uses of uninitialized variable",
    "id" : "2417581",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2417581"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.7",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H",
    "status" : "draft"
  },
  "details" : [ "Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application crash. An attack requires a crafted USB device or smart card that would present the system with specially crafted responses to the APDUs", "Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application crash. An attack requires a crafted USB device or smart card that would present the system with specially crafted responses to the APDUs" ],
  "statement" : "Physical access is required for a successful attack of this vulnerability which increases the complexity and lowers the severity of this flaw hence it was rated Low.",
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Fix deferred",
    "package_name" : "opensc",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Fix deferred",
    "package_name" : "opensc",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Fix deferred",
    "package_name" : "opensc",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Fix deferred",
    "package_name" : "opensc",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2025-13763\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-13763\nhttps://github.com/OpenSC/OpenSC/security/advisories/GHSA-2v44-fq35-98vv\nhttps://github.com/OpenSC/OpenSC/wiki/CVE-2025-13763" ],
  "name" : "CVE-2025-13763",
  "mitigation" : {
    "value" : "To mitigate this issue, avoid connecting untrusted USB devices or smart cards to systems running affected versions of Red Hat Enterprise Linux. This operational control reduces the risk of an attacker presenting a specially crafted device to exploit the uninitialized variable flaws in `libopensc`.",
    "lang" : "en:us"
  },
  "csaw" : false
}