CVE-2023-5992

Updated: 2026-02-27 01:17:08.159973

Description:

A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.9

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU opensc 0.22.0 5.9 MEDIUM Ignored 2025-10-11 00:21:46 Exposure exists only if a host uses OpenSC to perform RSA PKCS#1 v1.5 decryption and that operation ...