Explore top 10 tips to secure your open-source projects now. Read More
×
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-36728 http://linux.oracle.com/errata/ELSA-2026-36728.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: libtasn1-4.13-6.el8_10.i686.rpm libtasn1-4.13-6.el8_10.x86_64.rpm libtasn1-devel-4.13-6.el8_10.i686.rpm libtasn1-devel-4.13-6.el8_10.x86_64.rpm libtasn1-tools-4.13-6.el8_10.x86_64.rpm aarch64: libtasn1-4.13-6.el8_10.aarch64.rpm libtasn1-devel-4.13-6.el8_10.aarch64.rpm libtasn1-tools-4.13-6.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/libtasn1-4.13-6.el8_10.src.rpm Related CVEs: CVE-2025-13151 Description of changes: [4.13-6] - Backport the fix for CVE-2025-13151 (RHEL-139546) _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-28253 http://linux.oracle.com/errata/ELSA-2026-28253.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: libtasn1-4.16.0-10.el9_8.i686.rpm libtasn1-4.16.0-10.el9_8.x86_64.rpm libtasn1-devel-4.16.0-10.el9_8.i686.rpm libtasn1-devel-4.16.0-10.el9_8.x86_64.rpm libtasn1-tools-4.16.0-10.el9_8.x86_64.rpm aarch64: libtasn1-4.16.0-10.el9_8.aarch64.rpm libtasn1-devel-4.16.0-10.el9_8.aarch64.rpm libtasn1-tools-4.16.0-10.el9_8.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/libtasn1-4.16.0-10.el9_8.src.rpm Related CVEs: CVE-2025-13151 Description of changes: [4.16.0-10] - Backport the fix for CVE-2025-13151 (RHEL-139568) _______________________________________________ El-errata mailing list
Low: libtasn1 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:28235", "synopsis": "Low: libtasn1 security update", "severity": "SEVERITY_LOW", "topic": "An update is available for libtasn1.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "A library that provides Abstract Syntax Notation One (ASN.1, as specified by the X.680 ITU-T recommendation) parsing and structures management, and Distinguished Encoding Rules (DER, as per X.690) encoding and decoding functions.\n\nSecurity Fix(es):\n\n* libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string (CVE-2025-13151)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2427698", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2427698", "description": ""}], "cves": [{"name": "CVE-2025-13151", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13151", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.9", "cwe": "CWE-120"}], "references": [], "publishedAt": "2026-06-24T12:05:09.232192Z", "rpms": {"Rocky Linux 10": {"nvras": ["libtasn1-tools-0:4.20.0-5.el10_2.x86_64.rpm", "libtasn1-tools-debuginfo-0:4.20.0-5.el10_2.aarch64.rpm", "libtasn1-tools-0:4.20.0-5.el10_2.s390x.rpm", "libtasn1-tools-0:4.20.0-5.el10_2.ppc64le.rpm", "libtasn1-0:4.20.0-5.el10_2.ppc64le.rpm", "libtasn1-tools-debuginfo-0:4.20.0-5.el10_2.x86_64.rpm", "libtasn1-devel-0:4.20.0-5.el10_2.ppc64le.rpm", "libtasn1-0:4.20.0-5.el10_2.x86_64.rpm", "libtasn1-tools-debuginfo-0:4.20.0-5.el10_2.ppc64le.rpm","libtasn1-debugsource-0:4.20.0-5.el10_2.aarch64.rpm", "libtasn1-tools-0:4.20.0-5.el10_2.aarch64.rpm", "libtasn1-debuginfo-0:4.20.0-5.el10_2.x86_64.rpm", "libtasn1-debugsource-0:4.20.0-5.el10_2.s390x.rpm", "libtasn1-devel-0:4.20.0-5.el10_2.x86_64.rpm", "libtasn1-devel-0:4.20.0-5.el10_2.aarch64.rpm", "libtasn1-0:4.20.0-5.el10_2.aarch64.rpm", "libtasn1-debugsource-0:4.20.0-5.el10_2.ppc64le.rpm", "libtasn1-0:4.20.0-5.el10_2.s390x.rpm", "libtasn1-debugsource-0:4.20.0-5.el10_2.x86_64.rpm", "libtasn1-debuginfo-0:4.20.0-5.el10_2.s390x.rpm", "libtasn1-debuginfo-0:4.20.0-5.el10_2.ppc64le.rpm", "libtasn1-devel-0:4.20.0-5.el10_2.s390x.rpm", "libtasn1-0:4.20.0-5.el10_2.src.rpm", "libtasn1-tools-debuginfo-0:4.20.0-5.el10_2.s390x.rpm", "libtasn1-debuginfo-0:4.20.0-5.el10_2.aarch64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. libtasn1 receives a low-severity security update for Rocky Linux to address a denial of service risk. Learn more now.. rocky linux update libtasn1 security fix. . Severity: Low. LinuxSecurity.com Team
Low: libtasn1 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:28253", "synopsis": "Low: libtasn1 security update", "severity": "SEVERITY_LOW", "topic": "An update is available for libtasn1.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "A library that provides Abstract Syntax Notation One (ASN.1, as specified by the X.680 ITU-T recommendation) parsing and structures management, and Distinguished Encoding Rules (DER, as per X.690) encoding and decoding functions.\n\nSecurity Fix(es):\n\n* libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string (CVE-2025-13151)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2427698", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2427698", "description": ""}], "cves": [{"name": "CVE-2025-13151", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13151", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.9", "cwe": "CWE-120"}], "references": [], "publishedAt": "2026-06-24T12:03:26.635873Z", "rpms": {"Rocky Linux 9": {"nvras": ["libtasn1-0:4.16.0-10.el9_8.aarch64.rpm", "libtasn1-0:4.16.0-10.el9_8.i686.rpm", "libtasn1-0:4.16.0-10.el9_8.ppc64le.rpm", "libtasn1-0:4.16.0-10.el9_8.s390x.rpm", "libtasn1-0:4.16.0-10.el9_8.src.rpm", "libtasn1-0:4.16.0-10.el9_8.x86_64.rpm", "libtasn1-debuginfo-0:4.16.0-10.el9_8.aarch64.rpm", "libtasn1-debuginfo-0:4.16.0-10.el9_8.i686.rpm", "libtasn1-debuginfo-0:4.16.0-10.el9_8.ppc64le.rpm", "libtasn1-debuginfo-0:4.16.0-10.el9_8.s390x.rpm", "libtasn1-debuginfo-0:4.16.0-10.el9_8.x86_64.rpm","libtasn1-debugsource-0:4.16.0-10.el9_8.aarch64.rpm", "libtasn1-debugsource-0:4.16.0-10.el9_8.i686.rpm", "libtasn1-debugsource-0:4.16.0-10.el9_8.ppc64le.rpm", "libtasn1-debugsource-0:4.16.0-10.el9_8.s390x.rpm", "libtasn1-debugsource-0:4.16.0-10.el9_8.x86_64.rpm", "libtasn1-devel-0:4.16.0-10.el9_8.aarch64.rpm", "libtasn1-devel-0:4.16.0-10.el9_8.i686.rpm", "libtasn1-devel-0:4.16.0-10.el9_8.ppc64le.rpm", "libtasn1-devel-0:4.16.0-10.el9_8.s390x.rpm", "libtasn1-devel-0:4.16.0-10.el9_8.x86_64.rpm", "libtasn1-tools-0:4.16.0-10.el9_8.aarch64.rpm", "libtasn1-tools-0:4.16.0-10.el9_8.ppc64le.rpm", "libtasn1-tools-0:4.16.0-10.el9_8.s390x.rpm", "libtasn1-tools-0:4.16.0-10.el9_8.x86_64.rpm", "libtasn1-tools-debuginfo-0:4.16.0-10.el9_8.aarch64.rpm", "libtasn1-tools-debuginfo-0:4.16.0-10.el9_8.ppc64le.rpm", "libtasn1-tools-debuginfo-0:4.16.0-10.el9_8.s390x.rpm", "libtasn1-tools-debuginfo-0:4.16.0-10.el9_8.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Low-level libtasn1 security advisory for Rocky Linux reveals a denial of service risk. Immediate updates are crucial for system integrity.. libtasn1 security update, Rocky Linux, denial of service issues, security advisories. . Severity: Low. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for libtasn1 Announcement ID: SUSE-SU-2026:21142-1 Release Date: 2026-04-07T14:33:05Z Rating: moderate References: * bsc#1256341 Cross-References: * CVE-2025-13151 CVSS scores: * CVE-2025-13151 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-13151 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2025-13151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for libtasn1 fixes the following issues: * CVE-2025-13151: lack of validation of input data size leads to stack-based buffer overflow in `asn1_expend_octet_string` (bsc#1256341). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-484=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-484=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libtasn1-tools-4.21.0-160000.1.1 * libtasn1-tools-debuginfo-4.21.0-160000.1.1 * libtasn1-6-debuginfo-4.21.0-160000.1.1 * libtasn1-devel-4.21.0-160000.1.1 * libtasn1-debugsource-4.21.0-160000.1.1 * libtasn1-6-4.21.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libtasn1-tools-4.21.0-160000.1.1 * libtasn1-tools-debuginfo-4.21.0-160000.1.1 * libtasn1-6-debuginfo-4.21.0-160000.1.1 * libtasn1-devel-4.21.0-160000.1.1 * libtasn1-debugsource-4.21.0-160000.1.1 * libtasn1-6-4.21.0-160000.1.1 ## References: *https://www.suse.com/security/cve/CVE-2025-13151.html * https://bugzilla.suse.com/show_bug.cgi?id=1256341 . Update for libtasn1 addresses moderate stack-based buffer overflow issue, ensuring system stability and integrity.. libtasn1 update, SUSE patch, moderate security update, buffer overflow fix. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for libtasn1 Announcement ID: SUSE-SU-2026:21001-1 Release Date: 2026-04-07T14:45:56Z Rating: moderate References: * bsc#1256341 Cross-References: * CVE-2025-13151 CVSS scores: * CVE-2025-13151 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-13151 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2025-13151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for libtasn1 fixes the following issues: * CVE-2025-13151: lack of validation of input data size leads to stack-based buffer overflow in `asn1_expend_octet_string` (bsc#1256341). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-484=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libtasn1-debugsource-4.21.0-160000.1.1 * libtasn1-6-debuginfo-4.21.0-160000.1.1 * libtasn1-6-4.21.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-13151.html * https://bugzilla.suse.com/show_bug.cgi?id=1256341 . This update addresses a buffer overflow in libtasn1 for SUSE, ensuring system integrity and security.. libtasn1 update, SUSE Linux Micro, buffer overflow fix, security patch. . LinuxSecurity.com Team
Update to 4.21.0; fixes CVE-2025-13151. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-48a302496d 2026-03-30 00:14:59.309160+00:00 -------------------------------------------------------------------------------- Name : libtasn1 Product : Fedora 44 Version : 4.21.0 Release : 1.fc44 URL : https://www.gnu.org/software/libtasn1/ Summary : The ASN.1 library used in GNUTLS Description : A library that provides Abstract Syntax Notation One (ASN.1, as specified by the X.680 ITU-T recommendation) parsing and structures management, and Distinguished Encoding Rules (DER, as per X.690) encoding and decoding functions. -------------------------------------------------------------------------------- Update Information: Update to 4.21.0; fixes CVE-2025-13151 -------------------------------------------------------------------------------- ChangeLog: * Fri Mar 13 2026 Alexander Sosedkin - 4.21.0-1 - Update to 4.21.0; fixes CVE-2025-13151 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-48a302496d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 4.21.0; fixes CVE-2025-13151. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-4450956be5 2026-03-19 00:52:58.576835+00:00 -------------------------------------------------------------------------------- Name : libtasn1 Product : Fedora 43 Version : 4.21.0 Release : 1.fc43 URL : https://www.gnu.org/software/libtasn1/ Summary : The ASN.1 library used in GNUTLS Description : A library that provides Abstract Syntax Notation One (ASN.1, as specified by the X.680 ITU-T recommendation) parsing and structures management, and Distinguished Encoding Rules (DER, as per X.690) encoding and decoding functions. -------------------------------------------------------------------------------- Update Information: Update to 4.21.0; fixes CVE-2025-13151 -------------------------------------------------------------------------------- ChangeLog: * Mon Mar 16 2026 Alexander Sosedkin - 4.21.0-1 - Update to 4.21.0; fixes CVE-2025-13151 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-4450956be5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.