High [CVE-2026-59885] Denial of Service via crafted ASN.1 OBJECT IDENTIFIER
This high-severity Red Hat Linux advisory covers CVE-2026-59885 affecting Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.6 for RHEL 9.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
pyasn1 is a generic ASN.1 library for Python.
Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data.
The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values. This issue is fixed in version 0.6.4.
A flaw was found in pyasn1. The arc-size limit introduced for CVE-2026-23490 does not mitigate this issue.
Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-1050.
Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat AI Inference Server 3.3; and 32 more.
Affected products named by the advisory: Red Hat Hardened Images; Red Hat Migration Toolkit for Applications 8.2; Red Hat OpenShift AI 3.4; Red Hat Quay 3.12; and 28 more.
- < 0.6.4
Official advisory · high-confidence parse· fetched 6 days ago·verify at source
- 0.6.4
- python3.12-pyasn1-0:0.6.4-1.el8ap
- python3.12-pyasn1-0:0.6.4-1.el9ap
- rhaiis/model-opt-cuda-rhel9:1787601159
- jaeger-main-2.19.0-1.1.hum1
- mta/mta-rhel9-operator:1786481481
- rhoai/odh-kserve-storage-initializer-rhel9:1787073479
- rhoai/odh-llama-stack-core-rhel9:1786635926
- rhoai/odh-mlflow-rhel9:1787226790
- rhoai/odh-model-registry-job-async-upload-rhel9:1787361413
- rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9:1787073866
- rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9:1787073873
- rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9:1787073459
- rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9:1787073611
- rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9:1787073451
- rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9:1787073451
- rhoai/odh-th06-cpu-torch210-py312-rhel9:1787076778
- rhoai/odh-th06-cuda130-torch210-py312-rhel9:1787077779
- rhoai/odh-th06-rocm64-torch291-py312-rhel9:1787076481
- rhoai/odh-training-cuda128-torch29-py312-rhel9:1786611803
- rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:1787121387
- rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9:1787074331
- rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:1787073605
- rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:1787073546
- rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:1787073717
- rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9:1787073713
- rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9:1787073593
- quay/quay-rhel8:1786395065
- quay/quay-rhel8:1786170635
- quay/quay-rhel8:1785261506
- quay/quay-rhel8:1785950004
- RHSA-2026:50319
- RHSA-2026:50336
- RHSA-2026:59518
- RHSA-2026:40236
- RHSA-2026:56347
- RHSA-2026:60520
- RHSA-2026:53520
- RHSA-2026:52968
- RHSA-2026:48933
- RHSA-2026:50931
Official advisory · high-confidence parse· fetched 6 days ago·verify at source
Mitigation checklist
- Update to pyasn1 version 0.6.4 or later when available for your product stream. The impact is limited to availability (denial of service) — an attacker cannot access or modify data. Applications that do not process untrusted ASN.1 input are at reduced risk.
Official advisory · high-confidence parse· fetched 6 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.