Updated: 2026-02-27 01:17:08.159973
Description:
A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.
| Links | NIST | CIRCL | RHEL | Ubuntu |
| Severity | Score | |
|---|---|---|
| CVSS Version 2.x | 0.0 | |
| CVSS Version 3.x | MEDIUM | 5.9 |
| OS name | Project name | Version | Score | Severity | Status | Errata | Last updated | Statement |
|---|---|---|---|---|---|---|---|---|
| AlmaLinux 9.2 ESU | opensc | 0.22.0 | 5.9 | MEDIUM | Ignored | 2025-10-11 00:21:46 | Exposure exists only if a host uses OpenSC to perform RSA PKCS#1 v1.5 decryption and that operation ... |