Back Linuxsecurity Ubuntu 26.04 LTS pyasn1 Denial of Service Issues USN-8712
Find practical guidance for preventing, investigating, and responding to Linux security problems. Review Linux Privileges ×
Several security issues were fixed in pyasn1. Software Description: - pyasn1: ASN.1 library for Python Details: It was discovered that pyasn1 did not properly bound the size of long-form tag identifiers when parsing BER, CER, or DER encoded data. An attacker could possibly use this issue to cause applications decoding untrusted ASN.1 data to consume excessive CPU resources, resulting in a denial of service. (CVE-2026-59884) It was discovered that pyasn1 processed OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs. An attacker could possibly use this issue to cause applications decoding untrusted ASN.1 data to consume excessive CPU resources, resulting in a denial of service. (CVE-2026-59885) It was discovered that pyasn1 incorrectly handled conversion of decoded REAL values to Python float types. An attacker could possibly use this issue to cause applications decoding untrusted ASN.1 data to consume excessive CPU and memory resources, re... Read the Full Advisory
Several security issues were fixed in pyasn1.
Software Description:
- pyasn1: ASN.1 library for Python
It was discovered that pyasn1 did not properly bound the size of long-form
tag identifiers when parsing BER, CER, or DER encoded data. An attacker
could possibly use this issue to cause applications decoding untrusted
ASN.1 data to consume excessive CPU resources, resulting in a denial of
service. (CVE-2026-59884)
It was discovered that pyasn1 processed OBJECT IDENTIFIER and RELATIVE-OID
values in quadratic time relative to the number of arcs. An attacker could
possibly use this issue to cause applications decoding untrusted ASN.1 data
to consume excessive CPU resources, resulting in a denial of service.
It was discovered that pyasn1 incorrectly handled conversion of decoded
REAL values to Python float types. An attacker could possibly use this
issue to cause applications decoding untrusted ASN.1 data to consume
excessive CPU and memory resources, re...
The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS python3-pyasn1 0.6.3-1ubuntu0.1 Ubuntu 24.04 LTS python3-pyasn1 0.4.8-4ubuntu0.3 Ubuntu 22.04 LTS python3-pyasn1 0.4.8-1ubuntu0.3 In general, a standard system update will make all the necessary changes.
CVE-2026-59884, CVE-2026-59885, CVE-2026-59886
Ubuntu Security Notice USN-8712-1
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
