Описание
A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements in a certificate, libtasn1 takes much longer than expected, which can slow down or even crash the system. This flaw allows an attacker to send a specially crafted certificate, causing a denial of service attack.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | libtasn1 | Affected | ||
| Red Hat Enterprise Linux 6 | libtasn1 | Out of support scope | ||
| Red Hat Enterprise Linux 7 | libtasn1 | Out of support scope | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred | ||
| Red Hat Enterprise Linux 8 | libtasn1 | Fixed | RHSA-2025:4049 | 23.04.2025 |
| Red Hat Enterprise Linux 8 | libtasn1 | Fixed | RHSA-2025:4049 | 23.04.2025 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | gnutls | Fixed | RHSA-2026:33125 | 29.06.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | libtasn1 | Fixed | RHSA-2026:33125 | 29.06.2026 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | gnutls | Fixed | RHSA-2026:33125 | 29.06.2026 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | libtasn1 | Fixed | RHSA-2026:33125 | 29.06.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements in a certificate, libtasn1 takes much longer than expected, which can slow down or even crash the system. This flaw allows an attacker to send a specially crafted certificate, causing a denial of service attack.
A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements in a certificate, libtasn1 takes much longer than expected, which can slow down or even crash the system. This flaw allows an attacker to send a specially crafted certificate, causing a denial of service attack.
Libtasn1: inefficient der decoding in libtasn1 leading to potential remote dos
A flaw in libtasn1 causes inefficient handling of specific certificate ...
EPSS
5.3 Medium
CVSS3