Resource exhaustion in GnuTLS - CVE-2024-12243

 

Resource exhaustion in GnuTLS - CVE-2024-12243

Published: February 18, 2025 / Updated: April 30, 2026


Vulnerability identifier: #VU104044
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-12243
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to libtasn1 does not properly control consumption of internal resources when decoding certain DER-encoded certificate data. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

GnuTLS
Debian Linux
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
Gentoo Linux
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Red Hat Enterprise Linux Server - AUS
Slackware Linux
Basesystem Module
Certifications Module
openSUSE Leap
Ubuntu
openEuler
Anolis OS
Fedora
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Concert Software
IBM Observability with Instana
Netcool Operations Insight
Submariner
Service Interconnect
Multicluster GlobalHub
Red Hat Advanced Cluster Management for Kubernetes
APEX Cloud Platform for Red Hat OpenShift
Red Hat OpenShift Dev Spaces
Guardium Data Security Center (GDSC)
Storage Virtualize
Verify Identity Access Digital Credentials
Robotic Process Automation for Cloud Pak
APEX Cloud Platform for Microsoft Azure
SmartFabric OS10
Traffix SDC
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
LANTIME Operating System Firmware (LTOS)
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libgnutls-openssl27
libgnutls-openssl-devel
libgnutls-openssl27-debuginfo
gnutls-debugsource
libgnutls-devel
gnutls
libgnutls28-32bit
libgnutls28
libgnutls28-debuginfo
libgnutlsxx-devel
gnutls-debuginfo
libgnutls28-debuginfo-32bit
gnutls28 (Ubuntu package)
libgnutls30-debuginfo-32bit
libgnutls30-32bit
libgnutls30
libgnutls30-debuginfo
libgnutls30-hmac
libgnutls30 (Ubuntu package)
gnutls-utils
gnutls-devel
gnutls-help
libgnutls30-hmac-64bit
libgnutls30-64bit
libgnutls30-64bit-debuginfo
libgnutls-devel-64bit
libgnutls30-hmac-32bit
libgnutls30-32bit-debuginfo
libgnutls-devel-32bit
gnutls-guile-debuginfo
libgnutlsxx28
gnutls-guile
libgnutlsxx28-debuginfo
gnutls (Red Hat package)
gnutls28 (Debian package)
gnutls-dane
gnutls-doc
gnutls-c++
libgnutls30t64 (Ubuntu package)
libgnutlsxx30
libgnutlsxx30-debuginfo
net-libs/gnutls
nettle
IBM Security Verify Access
IBM API Connect
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
SmartFabric Manager
OpenShift API for Data Protection (OADP)
Red Hat OpenShift GitOps
Red Hat Ceph Storage
IBM CICS TX Advanced
IBM App Connect Enterprise

How to mitigate CVE-2024-12243

Install updates from vendor's website.

GnuTLS - update to 3.8.9
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.2.1
IBM Concert Software - update to 2.0.0
IBM Observability with Instana - update to 1.0.298
Netcool Operations Insight - update to 1.6.15
Guardium Data Security Center (GDSC) - update to 3.7.2
LANTIME Operating System Firmware (LTOS) - update to 7.08.021
IBM Qradar SIEM - update to 7.5.0 Update Pack 13
Storage Virtualize - addressed in versions 8.7.0.8, 9.1.0.2
IBM API Connect - update to 10.0.8.5
Robotic Process Automation for Cloud Pak - update to 23.0.20.3
Submariner - update to 0.20.1
Red Hat OpenShift Serverless - update to 1
SmartFabric Manager - update to 1.3.0
OpenShift API for Data Protection (OADP) - addressed in versions 1.3.7, 1.4.5
Service Interconnect - update to 1.4
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
Multicluster GlobalHub - update to 1.4.1
Migration Toolkit for Containers - update to 1.8.7
Red Hat OpenShift GitOps - addressed in versions 1.15.3, 1.16.1
Multicluster Engine for Kubernetes - addressed in versions 2.4.9, 2.5.9, 2.6.7, 2.6.8
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.9.9, 2.13.3
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
libgnutls-openssl27 - update to 3.3.27-3.9.1
libgnutls-openssl-devel - update to 3.3.27-3.9.1
libgnutls-openssl27-debuginfo - update to 3.3.27-3.9.1
gnutls-debugsource - addressed in versions 3.3.27-3.9.1, 3.4.17-8.17.1, 3.6.7-150200.14.34.1, 3.7.3-150400.4.47.1, 3.7.3-150400.11.1, 3.8.3-150600.4.6.2
libgnutls-devel - addressed in versions 3.3.27-3.9.1, 3.7.3-150400.4.47.1, 3.8.3-150600.4.6.2
gnutls - addressed in versions 3.3.27-3.9.1, 3.6.7-150200.14.34.1, 3.7.3-150400.4.47.1, 3.7.3-150400.11.1, 3.8.3-150600.4.6.2
libgnutls28-32bit - update to 3.3.27-3.9.1
libgnutls28 - update to 3.3.27-3.9.1
libgnutls28-debuginfo - update to 3.3.27-3.9.1
libgnutlsxx-devel - addressed in versions 3.3.27-3.9.1, 3.7.3-150400.4.47.1, 3.8.3-150600.4.6.2
gnutls-debuginfo - addressed in versions 3.3.27-3.9.1, 3.6.7-150200.14.34.1, 3.7.3-150400.4.47.1, 3.7.3-150400.11.1, 3.8.3-150600.4.6.2
libgnutls28-debuginfo-32bit - update to 3.3.27-3.9.1
gnutls28 (Ubuntu package) - addressed in versions 3.4.10-4ubuntu1.9+esm3, 3.5.18-1ubuntu1.6+esm3, 3.6.13-2ubuntu1.12+esm2
libgnutls30-debuginfo-32bit - update to 3.4.17-8.17.1
libgnutls30-32bit - addressed in versions 3.4.17-8.17.1, 3.7.3-150400.4.47.1, 3.8.3-150600.4.6.2
libgnutls30 - addressed in versions 3.4.17-8.17.1, 3.6.7-150200.14.34.1, 3.7.3-150400.4.47.1, 3.7.3-150400.11.1, 3.8.3-150600.4.6.2
libgnutls30-debuginfo - addressed in versions 3.4.17-8.17.1, 3.6.7-150200.14.34.1, 3.7.3-150400.4.47.1, 3.7.3-150400.11.1, 3.8.3-150600.4.6.2
libgnutls30-hmac - addressed in versions 3.6.7-150200.14.34.1, 3.7.3-150400.4.47.1, 3.7.3-150400.11.1
libgnutls30 (Ubuntu package) - addressed in versions 3.6.13-2ubuntu1.12, 3.7.3-4ubuntu1.6
gnutls-utils - addressed in versions 3.6.14-18, 3.7.2-15, 3.7.2-16, 3.8.2-5
gnutls-devel - addressed in versions 3.6.14-18, 3.7.2-15, 3.7.2-16, 3.8.2-5
gnutls-debugsource - addressed in versions 3.6.14-18, 3.7.2-15, 3.7.2-16, 3.8.2-5
gnutls-debuginfo - addressed in versions 3.6.14-18, 3.7.2-15, 3.7.2-16, 3.8.2-5
gnutls - addressed in versions 3.6.14-18, 3.7.2-15, 3.7.2-16, 3.8.2-5
gnutls-help - addressed in versions 3.6.14-18, 3.7.2-15, 3.7.2-16, 3.8.2-5
libgnutls30-hmac-64bit - update to 3.7.3-150400.4.47.1
libgnutls30-64bit - addressed in versions 3.7.3-150400.4.47.1, 3.8.3-150600.4.6.2
libgnutls30-64bit-debuginfo - addressed in versions 3.7.3-150400.4.47.1, 3.8.3-150600.4.6.2
libgnutls-devel-64bit - addressed in versions 3.7.3-150400.4.47.1, 3.8.3-150600.4.6.2
libgnutls30-hmac-32bit - update to 3.7.3-150400.4.47.1
libgnutls30-32bit-debuginfo - addressed in versions 3.7.3-150400.4.47.1, 3.8.3-150600.4.6.2
libgnutls-devel-32bit - addressed in versions 3.7.3-150400.4.47.1, 3.8.3-150600.4.6.2
gnutls-guile-debuginfo - update to 3.7.3-150400.4.47.1
libgnutlsxx28 - update to 3.7.3-150400.4.47.1
gnutls-guile - update to 3.7.3-150400.4.47.1
libgnutlsxx28-debuginfo - update to 3.7.3-150400.4.47.1
gnutls (Red Hat package) - update to 3.7.6-21.el9_2.4
gnutls28 (Debian package) - update to 3.7.9-2+deb12u4
gnutls-dane - update to 3.8.2-4
gnutls-doc - update to 3.8.2-4
gnutls-utils - update to 3.8.2-4
gnutls - update to 3.8.2-4
gnutls-c++ - update to 3.8.2-4
gnutls-devel - update to 3.8.2-4
gnutls-dane - update to 3.8.2-5
libgnutls30t64 (Ubuntu package) - addressed in versions 3.8.3-1.1ubuntu3.3, 3.8.6-2ubuntu1.1
libgnutlsxx30 - update to 3.8.3-150600.4.6.2
libgnutlsxx30-debuginfo - update to 3.8.3-150600.4.6.2
gnutls - update to 3.8.9
gnutls - addressed in versions 3.8.9-1.fc40, 3.8.9-2.fc41, 3.8.9-2.fc42, 3.8.9-4.fc43
net-libs/gnutls - update to 3.8.10
nettle - addressed in versions 3.10.1-1.fc42, 3.10.1-1.fc43
Red Hat OpenShift Dev Spaces - update to 3.21.0
Red Hat OpenShift Container Platform - addressed in versions 4.13.58, 4.14.51, 4.15.50, 4.16.44, 4.17.32, 4.18.16
Red Hat Ceph Storage - update to 8.1
IBM CICS TX Advanced - update to 10.1.0.0 ifix37
SmartFabric OS10 - addressed in versions 10.5.4.15, 10.5.5.14, 10.5.6.9, 10.6.0.3
IBM App Connect Enterprise - addressed in versions 12.0.13, 12.13.0

External References

Related Security Bulletins