Resource exhaustion in GnuTLS - CVE-2024-12243
Published: February 18, 2025 / Updated: April 30, 2026
GnuTLS
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to libtasn1 does not properly control consumption of internal resources when decoding certain DER-encoded certificate data. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.