RHSA-2026:4144HighCVSS 7.5
Red Hat Security Advisory: python-pyasn1 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-23490 — pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID
🎯 Affected products12
- Red Hat Enterprise Linux AppStream AUS (v.8.6)
- Red Hat Enterprise Linux AppStream E4S (v.8.6)
- Red Hat Enterprise Linux AppStream TUS (v.8.6)
- python-pyasn1-0:0.3.7-6.el8_6.1.src as a component of Red Hat Enterprise Linux AppStream AUS (v.8.6)
- python-pyasn1-0:0.3.7-6.el8_6.1.src as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6)
- python-pyasn1-0:0.3.7-6.el8_6.1.src as a component of Red Hat Enterprise Linux AppStream TUS (v.8.6)
- python3-pyasn1-0:0.3.7-6.el8_6.1.noarch as a component of Red Hat Enterprise Linux AppStream AUS (v.8.6)
- python3-pyasn1-0:0.3.7-6.el8_6.1.noarch as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6)
- python3-pyasn1-0:0.3.7-6.el8_6.1.noarch as a component of Red Hat Enterprise Linux AppStream TUS (v.8.6)
- python3-pyasn1-modules-0:0.3.7-6.el8_6.1.noarch as a component of Red Hat Enterprise Linux AppStream AUS (v.8.6)
- python3-pyasn1-modules-0:0.3.7-6.el8_6.1.noarch as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6)
- python3-pyasn1-modules-0:0.3.7-6.el8_6.1.noarch as a component of Red Hat Enterprise Linux AppStream TUS (v.8.6)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258