Stack-based buffer overflow in libtASN1 - CVE-2025-13151

 

Stack-based buffer overflow in libtASN1 - CVE-2025-13151

Published: January 12, 2026


Vulnerability identifier: #VU121181
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-13151
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a boundary error within the asn1_expend_octet_string() function. A remote attacker can pass specially crafted certificate to the application, trigger a stack-based buffer overflow and perform a denial of service attack..



Affected software

libtASN1
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Micro
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
openEuler
Fedora
IBM MQ Operator
Oracle Communications Cloud Native Core Network Exposure Function
IBM supplied MQ Advanced container images
Oracle Communications Cloud Native Core Network Slice Selection Function
Oracle Communications Cloud Native Core Unified Data Repository
libtasn1-6 (Ubuntu package)
libtasn1-6-debuginfo-32bit
libtasn1-debugsource
libtasn1-6-32bit
libtasn1-debuginfo
libtasn1-6
libtasn1-devel
libtasn1
libtasn1-6-debuginfo
libtasn1 (Red Hat package)
libtasn1-doc
libtasn1-tools
libtasn1-help

How to mitigate CVE-2025-13151

Install updates from vendor's website.

libtASN1 - update to 4.21.0
IBM MQ Operator - addressed in versions 3.2.26 SC2, 4.0.1 SC2
IBM supplied MQ Advanced container images - update to 10.0.0.0-r2
libtasn1-6 (Ubuntu package) - addressed in versions 3.4-3ubuntu0.6+esm1, 4.7-3ubuntu0.16.04.3+esm4, 4.13-2ubuntu0.1~esm1, 4.16.0-2ubuntu0.1+esm1, 4.18.0-4ubuntu0.2, 4.19.0-3ubuntu0.24.04.2, 4.20.0-2ubuntu0.25.04.1, 4.20.0-2ubuntu0.25.10.1
libtasn1-6-debuginfo-32bit - update to 4.9-3.19.1
libtasn1-debugsource - addressed in versions 4.9-3.19.1, 4.19.0-5.1
libtasn1-6-32bit - update to 4.9-3.19.1
libtasn1-debuginfo - update to 4.9-3.19.1
libtasn1-6 - addressed in versions 4.9-3.19.1, 4.19.0-5.1
libtasn1-devel - update to 4.9-3.19.1
libtasn1 - update to 4.9-3.19.1
libtasn1-6-debuginfo - addressed in versions 4.9-3.19.1, 4.19.0-5.1
libtasn1 (Red Hat package) - update to 4.13-6.el8_10
libtasn1-doc - addressed in versions 4.13-6.0.1, 4.19.0-5
libtasn1-devel - addressed in versions 4.13-6.0.1, 4.19.0-5
libtasn1 - addressed in versions 4.13-6.0.1, 4.19.0-5
libtasn1-tools - addressed in versions 4.13-6.0.1, 4.19.0-5
libtasn1 - addressed in versions 4.16.0-5, 4.19.0-3
libtasn1-debuginfo - addressed in versions 4.16.0-5, 4.19.0-3
libtasn1-debugsource - addressed in versions 4.16.0-5, 4.19.0-3
libtasn1-devel - addressed in versions 4.16.0-5, 4.19.0-3
libtasn1-help - addressed in versions 4.16.0-5, 4.19.0-3
libtasn1 - addressed in versions 4.21.0-1.fc43, 4.21.0-1.fc44

External References

Related Security Bulletins