Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-13151

Опубликовано: 07 янв. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.

A flaw was found in libtasn1. A remote attacker could exploit a stack-based buffer overflow vulnerability in the asn1_expend_octet_string function. This occurs due to a failure in validating the size of input data. Successful exploitation can lead to a Denial of Service (DoS) condition, making the affected system or application unavailable.

Отчет

This vulnerability is rated Low for Red Hat products. A stack-based buffer overflow in the libtasn1 library, specifically within the asn1_expend_octet_string function, can be triggered by failing to validate input data size. This could allow a remote, unauthenticated attacker to cause a denial of service in applications utilizing libtasn1.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libtasn1Fix deferred
Red Hat Enterprise Linux 7libtasn1Fix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Enterprise Linux 10libtasn1FixedRHSA-2026:2823523.06.2026
Red Hat Enterprise Linux 8libtasn1FixedRHSA-2026:3672808.07.2026
Red Hat Enterprise Linux 8libtasn1FixedRHSA-2026:3672808.07.2026
Red Hat Enterprise Linux 9libtasn1FixedRHSA-2026:2825323.06.2026
Red Hat Enterprise Linux 9libtasn1FixedRHSA-2026:2825323.06.2026
Red Hat Discovery 2discovery/discovery-server-rhel9FixedRHSA-2026:3331329.06.2026
Red Hat Discovery 2discovery/discovery-ui-rhel9FixedRHSA-2026:3331329.06.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2427698libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string

EPSS

Процентиль: 63%
0.01109
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
7 месяцев назад

Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.

CVSS3: 7.5
nvd
7 месяцев назад

Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.

CVSS3: 2.9
msrc
7 месяцев назад

CVE-2025-13151

CVSS3: 7.5
debian
7 месяцев назад

Stack-based buffer overflow in libtasn1 version: v4.20.0. The function ...

suse-cvrf
4 месяца назад

Security update for libtasn1

EPSS

Процентиль: 63%
0.01109
Низкий

5.9 Medium

CVSS3