Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-58261

Опубликовано: 27 июл. 2025
Источник: redhat
CVSS3: 2.9
EPSS Низкий

Описание

The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.

A flaw was found in sequoia-openpgp. Processing RawCertParser operations with unsupported primary key types triggers an infinite loop of error messages. This flaw allows a local attacker to provide a specially crafted certificate file, resulting in a denial of service due to resource exhaustion.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rust-rpm-sequoiaFix deferred
Red Hat Enterprise Linux 10rust-sequoia-sqNot affected
Red Hat Enterprise Linux 10rust-sequoia-sqvNot affected
Red Hat Enterprise Linux 10trustee-guest-componentsNot affected
Red Hat Enterprise Linux 9rust-rpm-sequoiaNot affected
Red Hat Enterprise Linux 9trustee-guest-componentsNot affected
Red Hat OpenShift Container Platform 4kata-containersFix deferred
Red Hat Trusted Profile Analyzerrhtpa/rhtpa-trustification-service-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2383774sequoia-openpgp: Sequoia OpenPGP: RawCertParser Infinite Loop Vulnerability

EPSS

Процентиль: 2%
0.00013
Низкий

2.9 Low

CVSS3

Связанные уязвимости

CVSS3: 2.9
ubuntu
5 месяцев назад

The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.

CVSS3: 2.9
nvd
5 месяцев назад

The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.

CVSS3: 2.9
debian
5 месяцев назад

The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infi ...

CVSS3: 2.9
github
больше 1 года назад

Low severity (DoS) vulnerability in sequoia-openpgp

EPSS

Процентиль: 2%
0.00013
Низкий

2.9 Low

CVSS3