---
id: CVE-2024-12133
title: A flaw in libtasn1 causes inefficient handling of specific certificate data
summary: >-
  A flaw in libtasn1 causes inefficient handling of specific certificate data.
  When processing a large number of elements in a certificate, libtasn1 takes
  much longer than expected, which can slow down or even crash the system. This
  flaw a…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-407
published: '2025-02-10'
updated: '2026-06-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-12133'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2025:17347'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:4049'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:7077'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:8021'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:8385'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:30849'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:30850'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2024-12133'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2344611'
    label: secalert@redhat.com
  - url: >-
      https://gitlab.com/gnutls/libtasn1/-/blob/master/doc/security/CVE-2024-12133.md
    label: secalert@redhat.com
  - url: 'https://gitlab.com/gnutls/libtasn1/-/issues/52'
    label: secalert@redhat.com
  - url: 'http://www.openwall.com/lists/oss-security/2025/02/06/6'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2025/02/msg00025.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20250523-0003/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-082556.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-202008.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
tags:
  - nvd
epss: 0.0111
epssPercentile: 0.64496
ingestedAt: '2026-06-26T16:43:13.407Z'
---

## Overview

A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements in a certificate, libtasn1 takes much longer than expected, which can slow down or even crash the system. This flaw allows an attacker to send a specially crafted certificate, causing a denial of service attack.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
