[WID-SEC-2025-0294] libtasn1: Schwachstelle ermöglicht Denial of Service CVSS Base Score 7.5 (hoch) CVSS Temporal Score 6.5 (mittel) Remoteangriff ja Datum 06.02.2025 Stand UPDATE 30.06.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Sonstiges UNIX Produktbeschreibung Libtasn1 ist die ASN.1 Bibliothek, welche z. B. von GnuTLS, GNU Shishi einigen anderen Paketen verwendet wird. Produkte UPDATE 04.01.2026 IBM Security Verify Access <10.0.9.1 UPDATE 16.11.2025 IBM Storwize UPDATE 05.10.2025 RESF Rocky Linux UPDATE 01.10.2025 Dell PowerProtect Data Domain <8.4.0.0 Dell PowerProtect Data Domain <7.10.1.70 Dell PowerProtect Data Domain <7.13.1.40 Dell PowerProtect Data Domain <8.3.1.10 UPDATE 06.08.2025 IBM QRadar SIEM <7.5.0 UP13 UPDATE 07.07.2025 IBM TXSeries Multiplatforms UPDATE 30.06.2025 IBM App Connect Enterprise Certified Containers Operands UPDATE 15.06.2025 IBM MQ Operator <3.6.0 CD IBM MQ Operator <3.2.13 SC2 IBM MQ Container <9.4.3.0-r1 UPDATE 12.06.2025 Amazon Linux 2 UPDATE 10.06.2025 Siemens SIMATIC S7 1500 CPU UPDATE 29.05.2025 Dell NetWorker Dell Avamar UPDATE 25.05.2025 NetApp ActiveIQ Unified Manager for VMware vSphere UPDATE 07.05.2025 Red Hat OpenShift Container Platform <4.15.50 UPDATE 23.04.2025 Red Hat Enterprise Linux UPDATE 22.04.2025 Oracle Linux UPDATE 18.02.2025 Ubuntu Linux UPDATE 17.02.2025 Fedora Linux UPDATE 13.02.2025 SUSE Linux UPDATE 10.02.2025 Debian Linux SUSE openSUSE 06.02.2025 Open Source libtasn1 <4.20.0 Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in libtasn1 ausnutzen, um einen Denial of Service Angriff durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
A vulnerability in the libtasn1 ASN.1 library (CVE not specified) allows a remote, anonymous attacker to cause a Denial of Service, with a CVSS Base Score of 7.5 (High). The core library is affected in versions prior to 4.20.0, and the vulnerability impacts a wide range of downstream products including IBM Security Verify Access, Red Hat Enterprise Linux, SUSE Linux, Dell PowerProtect Data Domain, and others, as listed in the detailed advisory. Mitigations are available, and administrators should consult the advisory for specific patching guidance for their affected systems.