Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-05145

Опубликовано: 16 янв. 2026
Источник: fstec
CVSS3: 7.5
CVSS2: 7.8
EPSS Низкий

Описание

Уязвимость ASN.1 библиотеки pyasn1 языка программирования Python связана с неограниченным распределением ресурсов. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, вызвать отказ в обслуживании

Вендор

Red Hat Inc.
ООО «РусБИТех-Астра»
ООО «Ред Софт»
АО «СберТех»
Сообщество свободного программного обеспечения

Наименование ПО

Red Hat Enterprise Linux
Red Hat OpenStack Platform
OpenShift Container Platform
Red Hat Quay
Openshift Service Mesh
Astra Linux Special Edition
Red Hat Openshift Data Foundation
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Satellite
Migration Toolkit for Virtualization
Migration Toolkit for Containers
OpenShift AI
Red Hat Ceph Storage
Red Hat OpenShift Lightspeed
Red Hat Trusted Artifact Signer
Red Hat AI Inference Server
Red Hat Discovery
РЕД ОС
Platform V SberLinux OS Server
Red Hat Enterprise Linux AI
Service Telemetry Framework
Red Hat Update Infrastructure
Fence Agents Remediation Operator
pyasn1
Ansible Automation Platform
Red Hat Directory Server

Версия ПО

8 (Red Hat Enterprise Linux)
13 (Red Hat OpenStack Platform)
4 (OpenShift Container Platform)
3 (Red Hat Quay)
2 (Openshift Service Mesh)
1.7 (Astra Linux Special Edition)
4.7 (Astra Linux Special Edition)
4 (Red Hat Openshift Data Foundation)
2 (Red Hat Advanced Cluster Management for Kubernetes)
6 (Red Hat Satellite)
9 (Red Hat Enterprise Linux)
16.2 (Red Hat OpenStack Platform)
8.2 Advanced Update Support (Red Hat Enterprise Linux)
- (Migration Toolkit for Virtualization)
8.4 Advanced Mission Critical Update Support (Red Hat Enterprise Linux)
17.1 (Red Hat OpenStack Platform)
- (Migration Toolkit for Containers)
9.0 Update Services for SAP Solutions (Red Hat Enterprise Linux)
8.6 Update Services for SAP Solutions (Red Hat Enterprise Linux)
8.6 Telecommunications Update Service (Red Hat Enterprise Linux)
8.6 Advanced Mission Critical Update Support (Red Hat Enterprise Linux)
7 Extended Lifecycle Support (Red Hat Enterprise Linux)
18.0 (Red Hat OpenStack Platform)
- (OpenShift AI)
9.4 Extended Update Support (Red Hat Enterprise Linux)
8 (Red Hat Ceph Storage)
- (Red Hat OpenShift Lightspeed)
- (Red Hat Trusted Artifact Signer)
10 (Red Hat Enterprise Linux)
8.8 Telecommunications Update Service (Red Hat Enterprise Linux)
8.8 Update Services for SAP Solutions (Red Hat Enterprise Linux)
9.2 Update Services for SAP Solutions (Red Hat Enterprise Linux)
- (Red Hat AI Inference Server)
3 (Openshift Service Mesh)
2 (Red Hat Discovery)
8.4 Extended Update Support Long-Life Add-On (Red Hat Enterprise Linux)
9.6 Extended Update Support (Red Hat Enterprise Linux)
8.0 (РЕД ОС)
10.0 Extended Update Support (Red Hat Enterprise Linux)
9.2.0-fstec (Platform V SberLinux OS Server)
3 (Red Hat Enterprise Linux AI)
1.5 (Service Telemetry Framework)
5 (Red Hat Update Infrastructure)
- (Fence Agents Remediation Operator)
0.4.8 (pyasn1)
2 (Ansible Automation Platform)
13 (Red Hat Directory Server)
0.6.1 (pyasn1)
до 9.2.0-fstec (Platform V SberLinux OS Server)

Тип ПО

Операционная система
ПО программно-аппаратного средства
Прикладное ПО информационных систем
Сетевое средство
ПО виртуализации/ПО виртуального программно-аппаратного средства
ПО для разработки ИИ

Операционные системы и аппаратные платформы

Red Hat Inc. Red Hat Enterprise Linux 8
ООО «РусБИТех-Астра» Astra Linux Special Edition 1.7
ООО «РусБИТех-Астра» Astra Linux Special Edition 4.7
Red Hat Inc. Red Hat Enterprise Linux 9
Red Hat Inc. Red Hat Enterprise Linux 8.2 Advanced Update Support
Red Hat Inc. Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red Hat Inc. Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
Red Hat Inc. Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
Red Hat Inc. Red Hat Enterprise Linux 8.6 Telecommunications Update Service
Red Hat Inc. Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red Hat Inc. Red Hat Enterprise Linux 7 Extended Lifecycle Support
Red Hat Inc. Red Hat Enterprise Linux 9.4 Extended Update Support
Red Hat Inc. Red Hat Enterprise Linux 10
Red Hat Inc. Red Hat Enterprise Linux 8.8 Telecommunications Update Service
Red Hat Inc. Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Red Hat Inc. Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Red Hat Inc. Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Red Hat Inc. Red Hat Enterprise Linux 9.6 Extended Update Support
ООО «Ред Софт» РЕД ОС 8.0
Red Hat Inc. Red Hat Enterprise Linux 10.0 Extended Update Support
АО «СберТех» Platform V SberLinux OS Server 9.2.0-fstec
Red Hat Inc. Red Hat Enterprise Linux AI 3
Red Hat Inc. Red Hat Directory Server 13
АО «СберТех» Platform V SberLinux OS Server до 9.2.0-fstec

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 7,8)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 7,5)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://github.com/pyasn1/pyasn1/security/advisories/GHSA-63vm-454h-vhhq
Для Platform V SberLinux OS Server:
Обновление операционной системы до версии 9.2.2-fstec
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-23490
Компенсирующие меры:
- минимизация пользовательских привилегий;
- отключение/удаление неиспользуемых учётных записей пользователей;
- контроль журналов аудита кластера для отслеживания попыток эксплуатации уязвимости.
Для Platform V SberLinux OS Server:
Обновление операционной системы до версии 9.2.2-fstec или выше
Для ОС Astra Linux:
обновить пакет pyasn1 до 0.4.2-3.astra1 или более высокой версии, используя рекомендации производителя: https://wiki.astralinux.ru/astra-linux-se17-bulletin-2026-0421SE17
Для Ред ОС:
https://redos.red-soft.ru/search/?iblock_id=24&q=CVE-2026-23490
Для ОС Astra Linux:
обновить пакет pyasn1 до 0.4.2-3.astra1 или более высокой версии, используя рекомендации производителя: https://wiki.astralinux.ru/astra-linux-se47-bulletin-2026-0518SE47

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Существует в открытом доступе

Информация об устранении

Уязвимость устранена

EPSS

Процентиль: 49%
0.00679
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Связанные уязвимости

CVSS3: 7.5
redos
3 месяца назад

Уязвимость python-pyasn1

CVSS3: 7.5
ubuntu
7 месяцев назад

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.

CVSS3: 7.5
redhat
7 месяцев назад

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.

CVSS3: 7.5
nvd
7 месяцев назад

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.

msrc
6 месяцев назад

pyasn1 has a DoS vulnerability in decoder

EPSS

Процентиль: 49%
0.00679
Низкий

7.5 High

CVSS3

7.8 High

CVSS2