Back

HIGH

CVE-2025-13151

Published Jan 7, 2026

Description

Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.

Affected products

Remediation

Red Hat statement

This vulnerability is rated Low for Red Hat products. A stack-based buffer overflow in the `libtasn1` library, specifically within the `asn1_expend_octet_string` function, can be triggered by failing to validate input data size. This could allow a remote, unauthenticated attacker to cause a denial of service in applications utilizing `libtasn1`.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published Jan 7, 2026
Updated Jan 20, 2026
Reserved Nov 13, 2025
CISA Vulnrichment
Updated Jan 7, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jan 7, 2026
ENISA EUVD
Assigner certcc
Published Jan 7, 2026
Updated Jan 20, 2026
Exploited since n/a
EUVD-2025-206262