Overview
A remote attacker can exploit this by providing specially crafted BER/CER/DER-encoded ASN.1 data with a large exponent in the REAL value. When the application subsequently prints, logs, compares, or performs arithmetic on the decoded value, this can cause excessive CPU and memory consumption, leading to a denial of service (DoS).
Vendor advisories
- RHSA-2026:59240 · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7 ELS) · released 2026-08-25 · advisory
- RHSA-2026:59329 · Red Hat · fixed in: Red Hat Enterprise Linux Server HighAvailability (v. 7 ELS), Red Hat Enterprise Linux Server ResilientStorage (v. 7 ELS), Red Hat Enterprise Linux Server for SAP ELS (v. 7), Red Hat Enterprise Linux Server for SAPHANA ELS (v. 7) · released 2026-08-25 · advisory
- RHSA-2026:59135 · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-08-24 · advisory
- RHSA-2026:50319 · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-08-04 · advisory
- RHSA-2026:59136 · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-08-24 · advisory
- RHSA-2026:50336 · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-08-04 · advisory
- RHSA-2026:59238 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-08-25 · advisory
- RHSA-2026:59243 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-08-25 · advisory
- RHSA-2026:53363 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8), Red Hat Enterprise Linux HighAvailability (v. 8), Red Hat Enterprise Linux ResilientStorage (v. 8) · released 2026-08-11 · advisory
- RHSA-2026:59241 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-08-25 · advisory
- RHSA-2026:58821 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.4), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4), Red Hat Enterprise Linux High Availability AUS (v.8.4), Red Hat Enterprise Linux HighAvailability EUS EXTENSION (v.8.4) · released 2026-08-24 · advisory
- Red Hat VEX · Important · affected: Exploit Intelligence, Lightspeed Core, Migration Toolkit for Applications 8, Migration Toolkit for Containers, Migration Toolkit for Virtualization, OpenShift Lightspeed, … · no fix planned: Red Hat Enterprise Linux 6, Exploit Intelligence, Migration Toolkit for Containers, Migration Toolkit for Virtualization, … · updated 2026-09-21 · vex
pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values — rated Important by Red Hat. Released 2026-07-14, updated 2026-09-21.
Affected:
- Exploit Intelligence
- Lightspeed Core
- Migration Toolkit for Applications 8
- Migration Toolkit for Containers
- Migration Toolkit for Virtualization
- OpenShift Lightspeed
- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Red Hat Ceph Storage 7
- Red Hat Ceph Storage 8
- Red Hat Ceph Storage 9
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenStack Platform 16.2
- Red Hat OpenStack Platform 17.1
- Red Hat OpenStack Platform 18.0
- Red Hat Satellite 6
- Service Telemetry Framework 1.5
Fixed:
- Red Hat Enterprise Linux Server (v. 7 ELS)
- Red Hat Enterprise Linux Server HighAvailability (v. 7 ELS)
- Red Hat Enterprise Linux Server ResilientStorage (v. 7 ELS)
- Red Hat Enterprise Linux Server for SAP ELS (v. 7)
- Red Hat Enterprise Linux Server for SAPHANA ELS (v. 7)
- Red Hat Ansible Automation Platform 2.5 for RHEL 8
- Red Hat Ansible Automation Platform 2.5 for RHEL 9
- Red Hat Ansible Automation Platform 2.6 for RHEL 9
- Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- Red Hat Enterprise Linux AppStream (v. 10)
- Red Hat Enterprise Linux AppStream (v. 8)
- Red Hat Enterprise Linux AppStream AUS (v.8.4)
- Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
- Red Hat Enterprise Linux AppStream AUS (v.8.6)
- Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)
- Red Hat Enterprise Linux AppStream E4S (v.8.8)
- Red Hat Enterprise Linux AppStream TUS (v.8.8)
- Red Hat Enterprise Linux AppStream E4S (v.9.2)
- Red Hat Enterprise Linux AppStream E4S (v.9.4)
- Red Hat Enterprise Linux AppStream EUS (v.9.6)
- Red Hat Enterprise Linux AppStream (v. 9)
- Red Hat Enterprise Linux HighAvailability (v. 8)
- Red Hat Enterprise Linux High Availability AUS (v.8.4)
- Red Hat Enterprise Linux HighAvailability EUS EXTENSION (v.8.4)
- Red Hat Enterprise Linux High Availability EUS EXTENSION (v.8.6)
- Red Hat Enterprise Linux High Availability E4S (v.8.8)
- Red Hat Enterprise Linux High Availability TUS (v.8.8)
- Red Hat Enterprise Linux High Availability E4S (v.9.2)
- Red Hat Enterprise Linux High Availability E4S (v.9.4)
- Red Hat AI Inference Server 3.3
- Red Hat Ansible Automation Platform 2.5
- Red Hat Ansible Automation Platform 2.6
- Red Hat Ansible Automation Platform 2.7
- Red Hat Enterprise Linux AI 3.3
- Red Hat Hardened Images
- Red Hat Migration Toolkit for Applications 8.2
- Red Hat OpenShift AI 3.4
- Red Hat Quay 3.10
- Red Hat Quay 3.12
- Red Hat Quay 3.15
No fix planned:
- Red Hat Enterprise Linux 6
- Exploit Intelligence
- Migration Toolkit for Containers
- Migration Toolkit for Virtualization
- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Red Hat Ceph Storage 7
- Red Hat Ceph Storage 8
- Red Hat Ceph Storage 9
- Lightspeed Core
- Migration Toolkit for Applications 8
- OpenShift Lightspeed
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenStack Platform 16.2
- Red Hat OpenStack Platform 17.1
- Red Hat OpenStack Platform 18.0
- Red Hat Satellite 6
- Service Telemetry Framework 1.5
Not affected:
- Red Hat Ansible Automation Platform 2.6 for RHEL 10
- Red Hat Ansible Automation Platform 2.5 for RHEL 8
- Red Hat Ansible Automation Platform 2.5 for RHEL 9
- Red Hat Ansible Automation Platform 2.6 for RHEL 9
- Red Hat Ansible Automation Platform 2.5
- Red Hat Ansible Automation Platform 2.6
- Red Hat Ansible Automation Platform 2.7
- Red Hat Enterprise Linux AI 3.3
- Red Hat Migration Toolkit for Applications 8.2
- Red Hat OpenShift AI 3.4
Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:59240
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:59329
For details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:59135
Workarounds / mitigations:
- When processing untrusted ASN.1 data with pyasn1, avoid calling prettyPrint(), str(), float(), int(), or performing comparisons or arithmetic on decoded Real (ASN.1 REAL type) objects. Instead, inspect the raw (mantissa, base, exponent) tuple directly. Where logging decoded ASN.1 structures is necessary, filter out or sanitize Real-typed values before conversion.
Package advisory (CVE-2026-59886)
Affected packages:
Patched in:
Source: https://osv.dev/vulnerability/GHSA-hm4w-wwcw-mr6r