GnuTLS Denial-of-Service Vulnerability via Inefficient DER Decoding in libtasn1

Vulnerability

A denial-of-service vulnerability has been identified in GnuTLS, which relies on libtasn1 for processing ASN.1 data. The issue arises from an inefficient algorithm in libtasn1 that can cause excessive delays when decoding certain DER-encoded certificate data. This flaw allows remote attackers to send specially crafted certificates that consume significant resources, making GnuTLS unresponsive or slow.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, causing GnuTLS to become unresponsive or slow, and increasing resource consumption.

Reproduction

The vulnerability can be reproduced by using the 'certtool' command-line utility included with GnuTLS. A crafted certificate that exploits the vulnerability should be saved as 'cert.pem'. When 'certtool' is run with this file, the CPU usage will spike to 100%, demonstrating the denial-of-service effect.

Remediation

Users can upgrade to GnuTLS versions 3.8.9 or later, where this vulnerability has been fixed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
2.5
exploitability
9.5
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.