CVE Vulnerabilities

CVE-2025-13763

Use of Uninitialized Variable

Published: Apr 23, 2026 | Modified: Apr 24, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.7 LOW
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application crash. An attack requires a crafted USB device or smart card that would present the system with specially crafted responses to the APDUs

Weakness

The code uses a variable that has not been initialized, leading to unpredictable or unintended results.

Affected Software

NameVendorStart VersionEnd Version
OpenscUbuntuesm-apps/xenial*
OpenscUbuntuupstream*

Potential Mitigations

References