Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-21895

Опубликовано: 08 янв. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

The rsa crate is an RSA implementation written in rust. Prior to version 0.9.10, when creating a RSA private key from its components, the construction panics instead of returning an error when one of the primes is 1. Version 0.9.10 fixes the issue.

A flaw was found in the RSA crate, an RSA implementation in Rust. When an application attempts to create an RSA private key from its components, a remote attacker could provide a malformed prime value of '1'. This invalid input causes the application to panic, leading to a Denial of Service (DoS).

Отчет

This vulnerability is rated Low for Red Hat products. The rsa crate, an RSA implementation in Rust, can panic when creating an RSA private key if one of the provided prime numbers is 1. This scenario requires specific, invalid input during key generation and does not affect standard RSA operations or key usage.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationbuild-of-trustee/trustee-rhel9Fix deferred
Confidential Compute Attestationconfidential-compute-attestation-tech-preview/trustee-rhel9Fix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-monitor-rhel9Fix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-operator-bundleFix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-builder-rhel9Fix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Fix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-rhel9-operatorFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-operator-bundleFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-rhel9-operatorFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/eventrouter-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-703
https://bugzilla.redhat.com/show_bug.cgi?id=2427935RSA: RSA crate: Denial of Service due to malformed prime in private key generation

EPSS

Процентиль: 5%
0.0002
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

The `rsa` crate is an RSA implementation written in rust. Prior to version 0.9.10, when creating a RSA private key from its components, the construction panics instead of returning an error when one of the primes is `1`. Version 0.9.10 fixes the issue.

CVSS3: 5.3
nvd
3 месяца назад

The `rsa` crate is an RSA implementation written in rust. Prior to version 0.9.10, when creating a RSA private key from its components, the construction panics instead of returning an error when one of the primes is `1`. Version 0.9.10 fixes the issue.

msrc
2 месяца назад

rsa crate has potential panic on a prime being equal to 1

CVSS3: 5.3
debian
3 месяца назад

The `rsa` crate is an RSA implementation written in rust. Prior to ver ...

github
3 месяца назад

rsa crate has potential panic on a prime being equal to 1

EPSS

Процентиль: 5%
0.0002
Низкий

5.5 Medium

CVSS3