he use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in the card enrolment process using pkcs15-init when a user or administrator enrols or modifies cards. An attacker must have physical access to the computer system and requires a crafted USB device or smart card to present the system with specially crafted responses to the APDUs, which are considered high complexity and low severity. This manipulation can allow for compromised card management operations during enrolment.
Configuration 1 (hide)
|
Configuration 2 (hide)
|
03 Nov 2025, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Nov 2024, 08:50
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| References | () https://access.redhat.com/security/cve/CVE-2024-1454 - Third Party Advisory | |
| References | () https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64898 - Issue Tracking | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2263929 - Issue Tracking, Third Party Advisory | |
| References | () https://github.com/OpenSC/OpenSC/commit/5835f0d4f6c033bd58806d33fa546908d39825c9 - Patch |
06 Nov 2024, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
16 Oct 2024, 13:57
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Fedoraproject fedora
Redhat enterprise Linux Opensc Project opensc Fedoraproject Opensc Project Redhat |
|
| CPE | cpe:2.3:a:opensc_project:opensc:*:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* |
|
| References | () https://access.redhat.com/security/cve/CVE-2024-1454 - Third Party Advisory | |
| References | () https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64898 - Issue Tracking | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2263929 - Issue Tracking, Third Party Advisory | |
| References | () https://github.com/OpenSC/OpenSC/commit/5835f0d4f6c033bd58806d33fa546908d39825c9 - Patch | |
| References | () https://lists.fedoraproject.org/archives/list/[email protected]/message/OWIZ5ZLO5ECYPLSTESCF7I7PQO5X6ZSU/ - Mailing List, Third Party Advisory | |
| References | () https://lists.fedoraproject.org/archives/list/[email protected]/message/RJI2FWLY24EOPALQ43YPQEZMEP3APPPI/ - Mailing List, Third Party Advisory | |
| References | () https://lists.fedoraproject.org/archives/list/[email protected]/message/UECKC7X4IM4YZQ5KRQMNBNKNOXLZC7RZ/ - Mailing List, Third Party Advisory |
Published : 2024-02-12 23:15
Updated : 2025-11-03 22:16
NVD link : CVE-2024-1454
Mitre link : CVE-2024-1454
CVE.ORG link : CVE-2024-1454
JSON object : View
Use After Free