CVE-2024-12243
Gnutls: gnutls impacted by inefficient der decoding in libtasn1 leading to remote dos
CVSS Score
5.3
EPSS Score
1.7%
EPSS Percentile
82th
A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libtasn1, decoding certain DER-encoded certificate data can take excessive time, leading to increased resource consumption. This flaw allows a remote attacker to send a specially crafted certificate, causing GnuTLS to become unresponsive or slow, resulting in a denial-of-service condition.
| CWE | CWE-407 |
| Published | Feb 10, 2025 |
| Last Updated | Mar 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for
Be the first to know when new medium vulnerabilities are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
Affected Versions
Red Hat / Red Hat Enterprise Linux 8
All versions affected Red Hat / Red Hat Enterprise Linux 8
All versions affected Red Hat / Red Hat Enterprise Linux 9
All versions affected Red Hat / Red Hat Enterprise Linux 9
All versions affected Red Hat / Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
All versions affected Red Hat / Red Hat Enterprise Linux 9.4 Extended Update Support
All versions affected Red Hat / Red Hat Discovery 1.14
All versions affected Red Hat / Red Hat Discovery 1.14
All versions affected Red Hat / Red Hat Enterprise Linux 10
All versions affected Red Hat / Red Hat Enterprise Linux 6
All versions affected Red Hat / Red Hat Enterprise Linux 7
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected References
access.redhat.com: https://access.redhat.com/errata/RHSA-2025:17361 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:4051 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:7076 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:8020 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:8385 access.redhat.com: https://access.redhat.com/security/cve/CVE-2024-12243 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2344615 gitlab.com: https://gitlab.com/gnutls/gnutls/-/issues/1553 gitlab.com: https://gitlab.com/gnutls/libtasn1/-/issues/52 lists.debian.org: https://lists.debian.org/debian-lts-announce/2025/02/msg00027.html security.netapp.com: https://security.netapp.com/advisory/ntap-20250523-0002/
Credits
Red Hat would like to thank Bing Shi for reporting this issue.