CVE-2024-12243: Gnutls: gnutls impacted by inefficient der decoding in libtasn1 leading to remote dos

Published Feb 10, 2025
·
Updated

A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libtasn1, decoding certain DER-encoded certificate data can take excessive time, leading to increased resource consumption. This flaw allows a remote attacker to send a specially crafted certificate, causing GnuTLS to become unresponsive or slow, resulting in a denial-of-service condition.

Other sources

Gnutls: gnutls impacted by inefficient der decoding in libtasn1 leading to remote dos

Microsoft

The issue is twofold: decoding a DER input with sequences and locating a specific element in a sequence. Even though a DER sequence is conceptually an array, in libtasn1 it is represented as a linked list, whose elements are assigned a string name, such as "?1". Therefore a simple lookup of an element at a given position is linear O(N) time complexity. When decoding a DER sequence, in each step libtasn1 looks up the parent node, recorded on the first element, which requires a backward linear search, resulting in O(N^2) time complexity.

Red Hat

Affected Software

7 affected componentsFixes available
F5 Traffix SDC=5.2.0
GNUTLS GNUTLS
libtasn1 libtasn1
IBM Concert Software<=1.0.0-1.1.0
Microsoft cbl2 gnutls 3.7.11-3
Microsoft azl3 gnutls 3.8.3-4
debian/gnutls28<=3.7.1-5+deb11u5
3.7.1-5+deb11u103.7.9-2+deb12u63.7.9-2+deb12u73.8.9-3+deb13u33.8.9-3+deb13u43.8.13-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/gnutls28 to a version that resolves this vulnerability.

    Fixed in 3.7.1-5+deb11u10Fixed in 3.7.9-2+deb12u6Fixed in 3.7.9-2+deb12u7Fixed in 3.8.9-3+deb13u3Fixed in 3.8.9-3+deb13u4Fixed in 3.8.13-1

Event History

Feb 10, 2025
Data Sourced
via Red Hat·08:40 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·03:28 PM
Data Sourced
via MITRE·03:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Mar 25, 2025
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
May 1, 2025
Advisory Published
via F5·11:27 PM
Aug 18, 2025
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Jul 6, 2026
Data Sourced
via Ubuntu·04:33 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·04:34 PM
DescriptionAffected Software
Data Sourced
via Launchpad·04:34 PM
Description

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-12243?

CVE-2024-12243 is classified as a medium severity vulnerability due to its potential to cause resource exhaustion.

2

How do I fix CVE-2024-12243?

To fix CVE-2024-12243, update to the latest versions of GnuTLS and libtasn1 that contain the security patch.

3

Who is affected by CVE-2024-12243?

CVE-2024-12243 affects users and applications that utilize GnuTLS and libtasn1 for ASN.1 data processing.

4

What are the implications of CVE-2024-12243?

The implications of CVE-2024-12243 include potential denial of service due to high resource consumption from processing malicious DER-encoded certificates.

5

How can attackers exploit CVE-2024-12243?

Attackers can exploit CVE-2024-12243 by sending specially crafted DER-encoded certificate data to the affected system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203