CVE-2024-12133
Libtasn1: inefficient der decoding in libtasn1 leading to potential remote dos
CVSS Score
5.3
EPSS Score
0.5%
EPSS Percentile
65th
A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements in a certificate, libtasn1 takes much longer than expected, which can slow down or even crash the system. This flaw allows an attacker to send a specially crafted certificate, causing a denial of service attack.
| CWE | CWE-407 |
| Published | Feb 10, 2025 |
| Last Updated | Mar 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for
Be the first to know when new medium vulnerabilities are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
Affected Versions
Red Hat / Red Hat Enterprise Linux 8
All versions affected Red Hat / Red Hat Enterprise Linux 8
All versions affected Red Hat / Red Hat Enterprise Linux 9
All versions affected Red Hat / Red Hat Enterprise Linux 9
All versions affected Red Hat / Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
All versions affected Red Hat / Red Hat Enterprise Linux 9.4 Extended Update Support
All versions affected Red Hat / Red Hat Discovery 1.14
All versions affected Red Hat / Red Hat Discovery 1.14
All versions affected Red Hat / Red Hat Enterprise Linux 10
All versions affected Red Hat / Red Hat Enterprise Linux 6
All versions affected Red Hat / Red Hat Enterprise Linux 7
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected References
access.redhat.com: https://access.redhat.com/errata/RHSA-2025:17347 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:4049 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:7077 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:8021 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:8385 access.redhat.com: https://access.redhat.com/security/cve/CVE-2024-12133 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2344611 gitlab.com: https://gitlab.com/gnutls/libtasn1/-/blob/master/doc/security/CVE-2024-12133.md gitlab.com: https://gitlab.com/gnutls/libtasn1/-/issues/52 openwall.com: http://www.openwall.com/lists/oss-security/2025/02/06/6 lists.debian.org: https://lists.debian.org/debian-lts-announce/2025/02/msg00025.html security.netapp.com: https://security.netapp.com/advisory/ntap-20250523-0003/
Credits
Red Hat would like to thank Bing Shi for reporting this issue.