A double free when handling responses from a smartcard in sc_file_set_sec_attr in libopensc/sc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
https://access.redhat.com/errata/RHSA-2019:2154
https://github.com/OpenSC/OpenSC/releases/tag/0.19.0-rc1
https://lists.debian.org/debian-lts-announce/2019/09/msg00009.html