Skip to content
VulniPulse
High7.5Red Hat Linux

High [CVE-2026-59885] Denial of Service via crafted ASN.1 OBJECT IDENTIFIER

This high-severity Red Hat Linux advisory covers CVE-2026-59885 affecting Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.6 for RHEL 9.

CVE-2026-59885 Published Jul 14, 2026Updated by vendor Jul 14, 2026
Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

pyasn1 is a generic ASN.1 library for Python.

Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data.

The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values. This issue is fixed in version 0.6.4.

A flaw was found in pyasn1. The arc-size limit introduced for CVE-2026-23490 does not mitigate this issue.

Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-1050.

Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat AI Inference Server 3.3; and 32 more.

Affected products named by the advisory: Red Hat Hardened Images; Red Hat Migration Toolkit for Applications 8.2; Red Hat OpenShift AI 3.4; Red Hat Quay 3.12; and 28 more.

Affected versions
  • < 0.6.4

Official advisory · high-confidence parse· fetched 6 days ago·verify at source

Fixed versions
  • 0.6.4
  • python3.12-pyasn1-0:0.6.4-1.el8ap
  • python3.12-pyasn1-0:0.6.4-1.el9ap
  • rhaiis/model-opt-cuda-rhel9:1787601159
  • jaeger-main-2.19.0-1.1.hum1
  • mta/mta-rhel9-operator:1786481481
  • rhoai/odh-kserve-storage-initializer-rhel9:1787073479
  • rhoai/odh-llama-stack-core-rhel9:1786635926
  • rhoai/odh-mlflow-rhel9:1787226790
  • rhoai/odh-model-registry-job-async-upload-rhel9:1787361413
  • rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9:1787073866
  • rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9:1787073873
  • rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9:1787073459
  • rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9:1787073611
  • rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9:1787073451
  • rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9:1787073451
  • rhoai/odh-th06-cpu-torch210-py312-rhel9:1787076778
  • rhoai/odh-th06-cuda130-torch210-py312-rhel9:1787077779
  • rhoai/odh-th06-rocm64-torch291-py312-rhel9:1787076481
  • rhoai/odh-training-cuda128-torch29-py312-rhel9:1786611803
  • rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:1787121387
  • rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9:1787074331
  • rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:1787073605
  • rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:1787073546
  • rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:1787073717
  • rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9:1787073713
  • rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9:1787073593
  • quay/quay-rhel8:1786395065
  • quay/quay-rhel8:1786170635
  • quay/quay-rhel8:1785261506
  • quay/quay-rhel8:1785950004
  • RHSA-2026:50319
  • RHSA-2026:50336
  • RHSA-2026:59518
  • RHSA-2026:40236
  • RHSA-2026:56347
  • RHSA-2026:60520
  • RHSA-2026:53520
  • RHSA-2026:52968
  • RHSA-2026:48933
  • RHSA-2026:50931

Official advisory · high-confidence parse· fetched 6 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Update to pyasn1 version 0.6.4 or later when available for your product stream. The impact is limited to availability (denial of service) — an attacker cannot access or modify data. Applications that do not process untrusted ASN.1 input are at reduced risk.

Official advisory · high-confidence parse· fetched 6 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.