Red Hat Product Errata RHSA-2026:28042 - Security Advisory Issued: 2026-06-22 Updated: 2026-06-22 RHSA-2026:28042 - Security Advisory Overview Updated Packages Synopsis Important: Red Hat OpenStack Platform 17.1 (python-pyasn1) security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for python-pyasn1 is now available for Red Hat OpenStack Platform 17.1 (Wallaby). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description This is an implementation of ASN.1 types and codecs in the Python programming language. Security Fix(es): pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID (CVE-2026-23490) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat OpenStack 17.1 for RHEL 8 x86_64 Red Hat OpenStack Director Deployment Tools 17.1 for RHEL 8 x86_64 Fixes BZ - 2430472 - CVE-2026-23490 pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID CVEs CVE-2026-23490 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat OpenStack 17.1 for RHEL 8 SRPM python-pyasn1-0.4.6-5.el8ost.src.rpm SHA-256: 12d0c3af363b4130f45168d143f6ec9245ef0174da63ef8c671acfd75566f7ec x86_64 python3-pyasn1-0.4.6-5.el8ost.noarch.rpm SHA-256: a4558a7b5555ac6199532795afeed8987697b99c709f1e7b232daf0521ec13b1 python3-pyasn1-modules-0.4.6-5.el8ost.noarch.rpm SHA-256: 9e6cf829725db75b7ba27d27cb5757e8d6b17204e003a1c7b05a8a86adc75ace Red Hat OpenStack Director Deployment Tools 17.1 for RHEL 8 SRPM python-pyasn1-0.4.6-5.el8ost.src.rpm SHA-256: 12d0c3af363b4130f45168d143f6ec9245ef0174da63ef8c671acfd75566f7ec x86_64 python3-pyasn1-0.4.6-5.el8ost.noarch.rpm SHA-256: a4558a7b5555ac6199532795afeed8987697b99c709f1e7b232daf0521ec13b1 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
A memory exhaustion denial-of-service vulnerability (CVE-2026-23490) exists in the python-pyasn1 library due to improper handling of malformed RELATIVE-OID objects. This security advisory, rated Important, affects Red Hat OpenStack Platform 17.1 (Wallaby). The fix is provided in the updated packages python-pyasn1-0.4.6-5.el8ost and python3-pyasn1-0.4.6-5.el8ost.