CVE-2024-1454
LOW EPSS 33.8%
Published Feb 12, 20242y ago · Modified Jun 17, 20261w ago
3.4 CVSS 3.1
Published Feb 12, 2024 2y ago
Last Modified Jun 17, 2026 1w ago
Description
The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in the card enrolment process using pkcs15-init when a user or administrator enrols or modifies cards. An attacker must have physical access to the computer system and requires a crafted USB device or smart card to present the system with specially crafted responses to the APDUs, which are considered high complexity and low severity. This manipulation can allow for compromised card management operations during enrolment.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N Attack Vector Physical
Attack Complexity High
Privileges Required None
User Interaction Required
Scope Changed
Confidentiality Low
Integrity Low
Availability None
Threat Intelligence
EPSS Exploit Probability
33.8% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 1
CWE-416 Use After Free Memory Safety
Affected Products 7
| Vendor | Product | Version | Range |
|---|---|---|---|
| opensc_project | opensc | * | <0.25.0 |
| fedoraproject | fedora | 38 | any |
| fedoraproject | fedora | 39 | any |
| fedoraproject | fedora | 40 | any |
| redhat | enterprise_linux | 7.0 | any |
| redhat | enterprise_linux | 8.0 | any |
| redhat | enterprise_linux | 9.0 | any |
References 8
- access.redhat.com https://access.redhat.com/security/cve/CVE-2024-1454
- bugs.chromium.org https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64898
- bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=2263929
- github.com https://github.com/OpenSC/OpenSC/commit/5835f0d4f6c033bd58806d33fa546908d39825c9
- lists.debian.org https://lists.debian.org/debian-lts-announce/2024/12/msg00026.html
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OWIZ5ZLO5ECYPLSTESCF7I7PQO5X6ZSU/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RJI2FWLY24EOPALQ43YPQEZMEP3APPPI/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UECKC7X4IM4YZQ5KRQMNBNKNOXLZC7RZ/
Remediation
- github.com https://github.com/OpenSC/OpenSC/commit/5835f0d4f6c033bd58806d33fa546908d39825c9