OESA-2026-1178

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-1178
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-1178.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2026-1178
Upstream
Published
2026-01-16T11:10:12Z
Modified
2026-08-18T01:19:33.538704041Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
libtasn1 security update
Details

Libtasn1 is the ASN.1 library used by GnuTLS, p11-kit and some other packages. The goal of this implementation is to be highly portable, and only require an ANSI C99 platform.This library provides Abstract Syntax Notation One (ASN.1, as specified by the X.680 ITU-T recommendation) parsing and structures management, and Distinguished Encoding Rules (DER, as per X.690) encoding and decoding functions.

Security Fix(es):

Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1expendoctet_string.(CVE-2025-13151)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:24.03-LTS / libtasn1

Package

Name
libtasn1
Purl
pkg:rpm/openEuler/libtasn1&distro=openEuler-24.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.19.0-3.oe2403

Ecosystem specific

{
    "aarch64": [
        "libtasn1-4.19.0-3.oe2403.aarch64.rpm",
        "libtasn1-debuginfo-4.19.0-3.oe2403.aarch64.rpm",
        "libtasn1-debugsource-4.19.0-3.oe2403.aarch64.rpm",
        "libtasn1-devel-4.19.0-3.oe2403.aarch64.rpm"
    ],
    "noarch": [
        "libtasn1-help-4.19.0-3.oe2403.noarch.rpm"
    ],
    "src": [
        "libtasn1-4.19.0-3.oe2403.src.rpm"
    ],
    "x86_64": [
        "libtasn1-4.19.0-3.oe2403.x86_64.rpm",
        "libtasn1-debuginfo-4.19.0-3.oe2403.x86_64.rpm",
        "libtasn1-debugsource-4.19.0-3.oe2403.x86_64.rpm",
        "libtasn1-devel-4.19.0-3.oe2403.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-1178.json"