Описание
Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.
A flaw was found in libtasn1. A remote attacker could exploit a stack-based buffer overflow vulnerability in the asn1_expend_octet_string function. This occurs due to a failure in validating the size of input data. Successful exploitation can lead to a Denial of Service (DoS) condition, making the affected system or application unavailable.
Отчет
This vulnerability is rated Low for Red Hat products. A stack-based buffer overflow in the libtasn1 library, specifically within the asn1_expend_octet_string function, can be triggered by failing to validate input data size. This could allow a remote, unauthenticated attacker to cause a denial of service in applications utilizing libtasn1.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | libtasn1 | Fix deferred | ||
| Red Hat Enterprise Linux 7 | libtasn1 | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred | ||
| Red Hat Enterprise Linux 10 | libtasn1 | Fixed | RHSA-2026:28235 | 23.06.2026 |
| Red Hat Enterprise Linux 8 | libtasn1 | Fixed | RHSA-2026:36728 | 08.07.2026 |
| Red Hat Enterprise Linux 8 | libtasn1 | Fixed | RHSA-2026:36728 | 08.07.2026 |
| Red Hat Enterprise Linux 9 | libtasn1 | Fixed | RHSA-2026:28253 | 23.06.2026 |
| Red Hat Enterprise Linux 9 | libtasn1 | Fixed | RHSA-2026:28253 | 23.06.2026 |
| Red Hat Discovery 2 | discovery/discovery-server-rhel9 | Fixed | RHSA-2026:33313 | 29.06.2026 |
| Red Hat Discovery 2 | discovery/discovery-ui-rhel9 | Fixed | RHSA-2026:33313 | 29.06.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.
Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.
Stack-based buffer overflow in libtasn1 version: v4.20.0. The function ...
EPSS
5.9 Medium
CVSS3