CVE-2025-13151
Published Jan 7, 2026
7.5
HIGHCVSS 3.1
EPSS 1.18%
Description
Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.
Affected products
-
- Version 0StatusaffectedConstraints<=4.20.0
- Version
No data.
Red Hat Discovery 2
discovery/discovery-server-rhel9:1782763840
Fixed · RHSA-2026:33313
Red Hat Discovery 2
discovery/discovery-ui-rhel9:1782756541
Fixed · RHSA-2026:33313
Red Hat Enterprise Linux 10
libtasn1-0:4.20.0-5.el10_2
Fixed · RHSA-2026:28235
Red Hat Enterprise Linux 8
libtasn1-0:4.13-6.el8_10
Fixed · RHSA-2026:36728
Red Hat Enterprise Linux 8
libtasn1-0:4.13-6.el8_10
Fixed · RHSA-2026:36728
Red Hat Enterprise Linux 9
libtasn1-0:4.16.0-10.el9_8
Fixed · RHSA-2026:28253
Red Hat Enterprise Linux 9
libtasn1-0:4.16.0-10.el9_8
Fixed · RHSA-2026:28253
Red Hat Hardened Images
libtasn1-main-4.21.0-1.1.hum1
Fixed · RHSA-2026:7500
Red Hat Insights proxy 1.5
insights-proxy/insights-proxy-container-rhel9:1782890503
Fixed · RHSA-2026:34102
Red Hat Update Infrastructure 5
rhui5/cds-kubernetes-rhel9:1784794818
Fixed · RHSA-2026:44481
Red Hat Update Infrastructure 5
rhui5/cds-kubernetes-tp-rhel9:1787241211
Fixed · RHSA-2026:58981
Red Hat Update Infrastructure 5
rhui5/cds-rhel9:1784794778
Fixed · RHSA-2026:44481
Red Hat Update Infrastructure 5
rhui5/haproxy-rhel9:1784795112
Fixed · RHSA-2026:44481
Red Hat Update Infrastructure 5
rhui5/installer-rhel9:1784794289
Fixed · RHSA-2026:44481
Red Hat Update Infrastructure 5
rhui5/installer-tp-rhel9:1787135742
Fixed · RHSA-2026:58981
Red Hat Update Infrastructure 5
rhui5/rhua-rhel9:1784795076
Fixed · RHSA-2026:44481
Red Hat Update Infrastructure 5
rhui5/rhua-tp-rhel9:1787241260
Fixed · RHSA-2026:58981
Red Hat Enterprise Linux 6
libtasn1
Fix deferred
Red Hat Enterprise Linux 7
libtasn1
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Discovery 2 | discovery/discovery-server-rhel9:1782763840 | Fixed | RHSA-2026:33313 |
| Red Hat Discovery 2 | discovery/discovery-ui-rhel9:1782756541 | Fixed | RHSA-2026:33313 |
| Red Hat Enterprise Linux 10 | libtasn1-0:4.20.0-5.el10_2 | Fixed | RHSA-2026:28235 |
| Red Hat Enterprise Linux 8 | libtasn1-0:4.13-6.el8_10 | Fixed | RHSA-2026:36728 |
| Red Hat Enterprise Linux 8 | libtasn1-0:4.13-6.el8_10 | Fixed | RHSA-2026:36728 |
| Red Hat Enterprise Linux 9 | libtasn1-0:4.16.0-10.el9_8 | Fixed | RHSA-2026:28253 |
| Red Hat Enterprise Linux 9 | libtasn1-0:4.16.0-10.el9_8 | Fixed | RHSA-2026:28253 |
| Red Hat Hardened Images | libtasn1-main-4.21.0-1.1.hum1 | Fixed | RHSA-2026:7500 |
| Red Hat Insights proxy 1.5 | insights-proxy/insights-proxy-container-rhel9:1782890503 | Fixed | RHSA-2026:34102 |
| Red Hat Update Infrastructure 5 | rhui5/cds-kubernetes-rhel9:1784794818 | Fixed | RHSA-2026:44481 |
| Red Hat Update Infrastructure 5 | rhui5/cds-kubernetes-tp-rhel9:1787241211 | Fixed | RHSA-2026:58981 |
| Red Hat Update Infrastructure 5 | rhui5/cds-rhel9:1784794778 | Fixed | RHSA-2026:44481 |
| Red Hat Update Infrastructure 5 | rhui5/haproxy-rhel9:1784795112 | Fixed | RHSA-2026:44481 |
| Red Hat Update Infrastructure 5 | rhui5/installer-rhel9:1784794289 | Fixed | RHSA-2026:44481 |
| Red Hat Update Infrastructure 5 | rhui5/installer-tp-rhel9:1787135742 | Fixed | RHSA-2026:58981 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-rhel9:1784795076 | Fixed | RHSA-2026:44481 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-tp-rhel9:1787241260 | Fixed | RHSA-2026:58981 |
| Red Hat Enterprise Linux 6 | libtasn1 | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | libtasn1 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability is rated Low for Red Hat products. A stack-based buffer overflow in the `libtasn1` library, specifically within the `asn1_expend_octet_string` function, can be triggered by failing to validate input data size. This could allow a remote, unauthenticated attacker to cause a denial of service in applications utilizing `libtasn1`.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (9)
- http://www.openwall.com/lists/oss-security/2026/01/08/5 Mailing ListPatch
- https://access.redhat.com/security/cve/CVE-2025-13151 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2427698 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-206262 Advisory
- https://gitlab.com/gnutls/libtasn1 Product
- https://gitlab.com/gnutls/libtasn1/-/merge_requests/121 patch
- https://nvd.nist.gov/vuln/detail/CVE-2025-13151
- https://www.cve.org/CVERecord?id=CVE-2025-13151
- https://www.kb.cert.org/vuls/id/271649 Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/01/08/5 | Mailing ListPatch | |
| https://access.redhat.com/security/cve/CVE-2025-13151 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2427698 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-206262 | Advisory | |
| https://gitlab.com/gnutls/libtasn1 | Product | |
| https://gitlab.com/gnutls/libtasn1/-/merge_requests/121 | patch | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-13151 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-13151 | ||
| https://www.kb.cert.org/vuls/id/271649 | Third Party Advisory |
Change history (0)
No recorded changes yet.