It was discovered that pyasn1, a generic ASN.1 library for Python, is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. This vulnerability can force the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consumes all available memory, crashing the host application.. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4557-1
It was discovered that pyasn1, a generic ASN.1 library for Python, is prone to a denial of service vulnerability when decoding ASN.1 data with deeply nested structures. For the oldstable distribution (bookworm), this problem has been fixed in version 0.4.8-3+deb12u2.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6194-1
Several security issues were fixed in pyasn1.. ========================================================================== Ubuntu Security Notice USN-8134-1 March 30, 2026 pyasn1 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in pyasn1. Software Description: - pyasn1: ASN.1 library for Python Details: It was discovered that pyasn1 could exhaust system resources when attempting to decode a malformed certificate. An attacker could possibly use this to cause a denial of service. (CVE-2026-23490) Kevin Tu discovered that pyasn1 could exhaust system resources via uncontrolled recursion when attempting to decode malicously-crafted certificates. An attacker could possibly use this to cause a denial of service. (CVE-2026-30922) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS pypy-pyasn1 0.4.2-3ubuntu0.20.04.1~esm1 Available with Ubuntu Pro python-pyasn1 0.4.2-3ubuntu0.20.04.1~esm1 Available with Ubuntu Pro python3-pyasn1 0.4.2-3ubuntu0.20.04.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS pypy-pyasn1 0.4.2-3ubuntu0.18.04.1~esm1 Available with Ubuntu Pro python-pyasn1 0.4.2-3ubuntu0.18.04.1~esm1 Available with Ubuntu Pro python3-pyasn1 0.4.2-3ubuntu0.18.04.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS pypy-pyasn1 0.1.9-1ubuntu0.1~esm1 Available with Ubuntu Pro python-pyasn1 0.1.9-1ubuntu0.1~esm1 Available with Ubuntu Pro python3-pyasn1 0.1.9-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 14.04 LTS python-pyasn1 0.1.7-1ubuntu2.1+esm1 Available with Ubuntu Pro python3-pyasn1 0.1.7-1ubuntu2.1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8134-1 CVE-2026-23490, CVE-2026-30922 . Several security issues fixed in pyasn1 for Ubuntu. Immediate update required to mitigate potential DoS attacks.. pyasn1 security update, ubunutu pyasn1 issues, DoS vulnerability pyasn1, Ubuntu security patch. . Severity: Critical. LinuxSecurity.com Team
pyasn1 could be made to consume resources and crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-8129-1 March 30, 2026 pyasn1 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: pyasn1 could be made to consume resources and crash if it received specially crafted input. Software Description: - pyasn1: ASN.1 library for Python Details: It was discovered that pyasn1 incorrectly handled recursion when decoding ASN.1 data. An attacker could use this issue to cause pyasn1 to consume resources, leading to a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 python3-pyasn1 0.6.1-1ubuntu0.2 Ubuntu 24.04 LTS python3-pyasn1 0.4.8-4ubuntu0.2 Ubuntu 22.04 LTS python3-pyasn1 0.4.8-1ubuntu0.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8129-1 CVE-2026-30922 Package Information: https://launchpad.net/ubuntu/+source/pyasn1/0.6.1-1ubuntu0.2 https://launchpad.net/ubuntu/+source/pyasn1/0.4.8-4ubuntu0.2 https://launchpad.net/ubuntu/+source/pyasn1/0.4.8-1ubuntu0.2 . Security Notice USN-8129-1 addresses a critical DoS issue in pyasn1 for Ubuntu releases. Update now to protect your system.. Ubuntu Security, pyasn1 DoS, Ubuntu 22.04 security update, Ubuntu 24.04 fix. . Severity: Critical. LinuxSecurity.com Team
It was discovered that pyasn1, a generic ASN.1 library for Python, is prone to a denial of service vulnerability, which may result in memory exhaustion from malformed OID/RELATIVE-OID with excessive continuation octets. For Debian 11 bullseye, this problem has been fixed in version. Debian LTS Advisory DLA-4463-1
It was discovered that pyasn1, a generic ASN.1 library for Python, is prone to a denial of service vulnerability, which may result in memory exhaustion from malformed OID/RELATIVE-OID with excessive continuation octets. For the oldstable distribution (bookworm), this problem has been fixed. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6114-1
pyasn1 could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-7975-1 January 22, 2026 pyasn1 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: pyasn1 could be made to crash if it received specially crafted input. Software Description: - pyasn1: ASN.1 library for Python Details: It was discovered that pyasn1 incorrectly handled malformed RELATIVE-OIDs with excessive continuation octets. An attacker could possibly use this issue to cause pyasn1 to consume memory, leading to a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 python3-pyasn1 0.6.1-1ubuntu0.1 Ubuntu 24.04 LTS python3-pyasn1 0.4.8-4ubuntu0.1 Ubuntu 22.04 LTS python3-pyasn1 0.4.8-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7975-1 CVE-2026-23490 Package Information: https://launchpad.net/ubuntu/+source/pyasn1/0.6.1-1ubuntu0.1 https://launchpad.net/ubuntu/+source/pyasn1/0.4.8-4ubuntu0.1 https://launchpad.net/ubuntu/+source/pyasn1/0.4.8-1ubuntu0.1 . Ensure your Ubuntu system is secured by updating pyasn1 to mitigate denial of service vulnerabilities caused by malformed inputs.. Python ASN.1 Library, Ubuntu Security Notice, Denial of Service, pyasn1 Update. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.