RHSA-2026:36728: Low: libtasn1 security update
A library that provides Abstract Syntax Notation One (ASN.1, as specified by the X.680 ITU-T recommendation) parsing and structures management, and Distinguished Encoding Rules (DER, as per X.690) encoding and decoding functions.Security Fix(es): libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1expendoctetstring (CVE-2025-13151) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libtasn1to a version that resolves this vulnerability.Fixed in 4.13-6.el8_10 - Upgrade
Upgrade
redhat/libtasn1-debuginfoto a version that resolves this vulnerability.Fixed in 4.13-6.el8_10 - Upgrade
Upgrade
redhat/libtasn1-debugsourceto a version that resolves this vulnerability.Fixed in 4.13-6.el8_10 - Upgrade
Upgrade
redhat/libtasn1-develto a version that resolves this vulnerability.Fixed in 4.13-6.el8_10 - Upgrade
Upgrade
redhat/libtasn1-toolsto a version that resolves this vulnerability.Fixed in 4.13-6.el8_10 - Upgrade
Upgrade
redhat/libtasn1-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.13-6.el8_10 - Upgrade
Upgrade
redhat/libtasn1to a version that resolves this vulnerability.Fixed in 4.13-6.el8_10.aa - Upgrade
Upgrade
redhat/libtasn1-debuginfoto a version that resolves this vulnerability.Fixed in 4.13-6.el8_10.aa - Upgrade
Upgrade
redhat/libtasn1-debugsourceto a version that resolves this vulnerability.Fixed in 4.13-6.el8_10.aa - Upgrade
Upgrade
redhat/libtasn1-develto a version that resolves this vulnerability.Fixed in 4.13-6.el8_10.aa - Upgrade
Upgrade
redhat/libtasn1-toolsto a version that resolves this vulnerability.Fixed in 4.13-6.el8_10.aa - Upgrade
Upgrade
redhat/libtasn1-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.13-6.el8_10.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:36728?
The severity of RHSA-2026:36728 is rated as low.
What does RHSA-2026:36728 address?
RHSA-2026:36728 addresses a security update for the libtasn1 library.
How do I fix RHSA-2026:36728?
To fix RHSA-2026:36728, apply the security update provided by Red Hat for your specific system architecture.
Which software is affected by RHSA-2026:36728?
RHSA-2026:36728 affects various versions of Red Hat Enterprise Linux across multiple architectures, including IBM z Systems, x86_64, Power, and ARM.
When was RHSA-2026:36728 published?
RHSA-2026:36728 was published on July 8, 2026.