CVE-2026-23490

high
Published 2026-01-16 Β· Modified 2026-03-10
CVSS v3
β€”
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
8.0

Description

RHSA-2026:4146: python-pyasn1 security update (Important)

Predictions

Exploit likelihood
30%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID CVSS v3: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Ansible Automation Platform 2.5 for RHEL 8python3.12-pyasn1-0:0.6.3-1.el8apRHSA-2026:135122026-05-04T00:00:00Z Red Hat Ansible Automation Platform 2.5 for RHEL…

Description

pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID

CVSS v3: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Ansible Automation Platform 2.5 for RHEL 8python3.12-pyasn1-0:0.6.3-1.el8apRHSA-2026:135122026-05-04T00:00:00Z
Red Hat Ansible Automation Platform 2.5 for RHEL 8automation-controller-0:4.6.26-1.el8apRHSA-2026:39592026-03-06T00:00:00Z
Red Hat Ansible Automation Platform 2.5 for RHEL 9python3.12-pyasn1-0:0.6.3-1.el9apRHSA-2026:135122026-05-04T00:00:00Z
Red Hat Ansible Automation Platform 2.5 for RHEL 9automation-controller-0:4.6.26-1.el9apRHSA-2026:39592026-03-06T00:00:00Z
Red Hat Ansible Automation Platform 2.6 for RHEL 9python3.12-pyasn1-0:0.6.3-1.el9apRHSA-2026:135082026-05-04T00:00:00Z
Red Hat Ansible Automation Platform 2.6 for RHEL 9automation-controller-0:4.7.9-1.el9apRHSA-2026:39582026-03-06T00:00:00Z
Red Hat Enterprise Linux 10fence-agents-0:4.16.0-13.el10_1.2RHSA-2026:19052026-02-04T00:00:00Z
Red Hat Enterprise Linux 10python-pyasn1-0:0.6.2-1.el10_1RHSA-2026:33542026-02-25T00:00:00Z
Red Hat Enterprise Linux 10.0 Extended Update Supportfence-agents-0:4.16.0-5.el10_0.8RHSA-2026:23092026-02-09T00:00:00Z
Red Hat Enterprise Linux 10.0 Extended Update Supportpython-pyasn1-0:0.6.2-1.el10_0.1RHSA-2026:41382026-03-10T00:00:00Z
Red Hat Enterprise Linux 7 Extended Lifecycle Supportresource-agents-0:4.1.1-61.el7_9.23RHSA-2026:27582026-02-16T00:00:00Z
Red Hat Enterprise Linux 7 Extended Lifecycle Supportresource-agents-0:4.1.1-61.el7_9.23RHSA-2026:27582026-02-16T00:00:00Z
Red Hat Enterprise Linux 7 Extended Lifecycle Supportpython-pyasn1-0:0.1.9-7.el7_9.2RHSA-2026:41482026-03-10T00:00:00Z
Red Hat Enterprise Linux 8fence-agents-0:4.2.1-129.el8_10.21RHSA-2026:19062026-02-04T00:00:00Z
Red Hat Enterprise Linux 8python-pyasn1-0:0.3.7-6.el8_10.1RHSA-2026:41462026-03-10T00:00:00Z
Red Hat Enterprise Linux 8resource-agents-0:4.9.0-54.el8_10.28RHSA-2026:19042026-02-04T00:00:00Z
Red Hat Enterprise Linux 8.2 Advanced Update Supportpython-pyasn1-0:0.3.7-6.el8_2.1RHSA-2026:41452026-03-10T00:00:00Z
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportfence-agents-0:4.2.1-65.el8_4.27RHSA-2026:24832026-02-10T00:00:00Z
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportpython-pyasn1-0:0.3.7-6.el8_4.1RHSA-2026:41472026-03-10T00:00:00Z
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportresource-agents-0:4.1.1-90.el8_4.23RHSA-2026:27122026-02-16T00:00:00Z
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-Onfence-agents-0:4.2.1-65.el8_4.27RHSA-2026:24832026-02-10T00:00:00Z
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-Onpython-pyasn1-0:0.3.7-6.el8_4.1RHSA-2026:41472026-03-10T00:00:00Z
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-Onresource-agents-0:4.1.1-90.el8_4.23RHSA-2026:27122026-02-16T00:00:00Z
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportfence-agents-0:4.2.1-89.el8_6.21RHSA-2026:24862026-02-10T00:00:00Z
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportpython-pyasn1-0:0.3.7-6.el8_6.1RHSA-2026:41442026-03-10T00:00:00Z
Red Hat Enterprise Linux 8.6 Telecommunications Update Servicefence-agents-0:4.2.1-89.el8_6.21RHSA-2026:24862026-02-10T00:00:00Z
Red Hat Enterprise Linux 8.6 Telecommunications Update Servicepython-pyasn1-0:0.3.7-6.el8_6.1RHSA-2026:41442026-03-10T00:00:00Z
Red Hat Enterprise Linux 8.6 Telecommunications Update Serviceresource-agents-0:4.9.0-16.el8_6.20RHSA-2026:24532026-02-10T00:00:00Z
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionsfence-agents-0:4.2.1-89.el8_6.21RHSA-2026:24862026-02-10T00:00:00Z
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionspython-pyasn1-0:0.3.7-6.el8_6.1RHSA-2026:41442026-03-10T00:00:00Z
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionsresource-agents-0:4.9.0-16.el8_6.20RHSA-2026:24532026-02-10T00:00:00Z
Red Hat Enterprise Linux 8.8 Telecommunications Update Servicefence-agents-0:4.2.1-112.el8_8.16RHSA-2026:22212026-02-09T00:00:00Z
Red Hat Enterprise Linux 8.8 Telecommunications Update Servicepython-pyasn1-0:0.3.7-6.el8_8.1RHSA-2026:41392026-03-10T00:00:00Z
Red Hat Enterprise Linux 8.8 Telecommunications Update Serviceresource-agents-0:4.9.0-40.el8_8.16RHSA-2026:24602026-02-10T00:00:00Z
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutionsfence-agents-0:4.2.1-112.el8_8.16RHSA-2026:22212026-02-09T00:00:00Z
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutionspython-pyasn1-0:0.3.7-6.el8_8.1RHSA-2026:41392026-03-10T00:00:00Z
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutionsresource-agents-0:4.9.0-40.el8_8.16RHSA-2026:24602026-02-10T00:00:00Z
Red Hat Enterprise Linux 9fence-agents-0:4.10.0-98.el9_7.5RHSA-2026:19032026-02-04T00:00:00Z
Red Hat Enterprise Linux 9python-pyasn1-0:0.4.8-7.el9_7RHSA-2026:33592026-02-25T00:00:00Z
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutionsfence-agents-0:4.10.0-20.el9_0.28RHSA-2026:23032026-02-09T00:00:00Z
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutionspython-pyasn1-0:0.4.8-6.el9_0.1RHSA-2026:41402026-03-10T00:00:00Z
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutionsfence-agents-0:4.10.0-43.el9_2.19RHSA-2026:23002026-02-09T00:00:00Z
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutionspython-pyasn1-0:0.4.8-6.el9_2.1RHSA-2026:41422026-03-10T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportfence-agents-0:4.10.0-62.el9_4.22RHSA-2026:23022026-02-09T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportpython-pyasn1-0:0.4.8-6.el9_4.1RHSA-2026:41432026-03-10T00:00:00Z
Red Hat Enterprise Linux 9.6 Extended Update Supportfence-agents-0:4.10.0-86.el9_6.15RHSA-2026:22992026-02-09T00:00:00Z
Red Hat Enterprise Linux 9.6 Extended Update Supportpython-pyasn1-0:0.4.8-6.el9_6.1RHSA-2026:41412026-03-10T00:00:00Z
Red Hat OpenShift Container Platform 4.17python-pyasn1-0:0.5.1-4.el9RHSA-2026:175952026-05-20T00:00:00Z
Red Hat OpenShift Container Platform 4.18python-pyasn1-0:0.5.1-4.el9RHSA-2026:174462026-05-20T00:00:00Z
Red Hat Ansible Automation Platform 2.5ansible-automation-platform-25/ee-supported-rhel8:1777398315RHSA-2026:135532026-05-04T00:00:00Z
Red Hat Ansible Automation Platform 2.5ansible-automation-platform-25/platform-resource-runner-rhel8:1777402264RHSA-2026:135532026-05-04T00:00:00Z
Red Hat Ansible Automation Platform 2.6ansible-automation-platform-26/eda-controller-rhel9:1777296732RHSA-2026:135452026-05-04T00:00:00Z
Red Hat Ansible Automation Platform 2.6ansible-automation-platform-26/ee-supported-rhel9:1777391447RHSA-2026:135452026-05-04T00:00:00Z
Red Hat Ceph Storage 8rhceph/rhceph-8-rhel9:1774002867RHSA-2026:56062026-03-24T00:00:00Z
Red Hat Enterprise Linux AI 3.3rhelai3/bootc-azure-rocm-rhel9:1778677745RHSA-2026:176112026-05-14T00:00:00Z
Red Hat Enterprise Linux AI 3.3rhelai3/bootc-rocm-rhel9:1778666124RHSA-2026:176112026-05-14T00:00:00Z
Red Hat OpenShift AI 3.3rhoai/odh-feature-server-rhel9:1778239104RHSA-2026:197122026-05-20T00:00:00Z
Red Hat OpenShift AI 3.3rhoai/odh-kserve-storage-initializer-rhel9:1778263407RHSA-2026:197122026-05-20T00:00:00Z
Red Hat OpenShift AI 3.3rhoai/odh-mlflow-rhel9:1778791600RHSA-2026:197122026-05-20T00:00:00Z
Red Hat OpenShift AI 3.3rhoai/odh-training-cuda128-torch29-py312-rhel9:1779123334RHSA-2026:197122026-05-20T00:00:00Z

Package state

ProductPackageState
Lightspeed Corelightspeed-core/dataverse-exporter-rhel9Affected
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Affected
Migration Toolkit for Containersrhmtc/openshift-migration-hook-runner-rhel8Affected
Migration Toolkit for Containersrhmtc/openshift-migration-rhel8-operatorAffected
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-rhel9-operatorWill not fix
Migration Toolkit for Virtualizationmtv-candidate/mtv-rhel9-operatorAffected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-to-dataverse-exporter-rhel9Affected
OpenShift Service Mesh 3openshift-service-mesh/kiali-rhel9-operatorNot affected
Red Hat AI Inference Serverrhaiis/vllm-rocm-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-minimal-rhel8Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-minimal-rhel9Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/lightspeed-rhel8Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/ee-minimal-rhel8Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/ee-minimal-rhel9Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-chatbot-rhel8Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/controller-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/controller-rhel9-operatorNot affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/eda-controller-rhel9-operatorNot affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/gateway-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/gateway-rhel9-operatorNot affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/hub-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/hub-rhel9-operatorNot affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-chatbot-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-rhel9-operatorNot affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/platform-resource-rhel9-operatorNot affected
Red Hat Ansible Automation Platform 2python3.11-pyasn1Not affected
Red Hat Ansible Automation Platform 2python3.11-pyasn1-modulesNot affected
Red Hat Ansible Automation Platform 2python3.12-pyasn1-modulesNot affected
Red Hat Ansible Automation Platform 2python3x-pyasn1Not affected
Red Hat Enterprise Linux 6python-pyasn1Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-agent-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-controller-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-router-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-llama-stack-core-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-runtime-generic-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-modelmesh-runtime-adapter-rhel8Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-trustyai-nemo-guardrails-server-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9Affected

Apply commands

bash fix
Apply RHSA-2026:13512 for Red Hat Ansible Automation Platform 2.5 for RHEL 8
yum update -y python3
# or:
dnf upgrade -y python3

Affected

VendorProductVersion
redhatLightspeed CoreAffected
redhatLightspeed CoreAffected
redhatMigration Toolkit for ContainersAffected
redhatMigration Toolkit for ContainersAffected
redhatMigration Toolkit for VirtualizationAffected
redhatOpenShift LightspeedAffected
redhatOpenShift LightspeedAffected
redhatOpenShift Service Mesh 3Not affected
redhatRed Hat AI Inference ServerAffected
redhatRed Hat AI Inference ServerAffected
redhatRed Hat Ansible Automation Platform 2Affected
redhatRed Hat Ansible Automation Platform 2Affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Ansible Automation Platform 2Affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Ansible Automation Platform 2Not affected
redhatRed Hat Enterprise Linux 6Not affected
redhatRed Hat OpenShift AI (RHOAI)Not affected
redhatRed Hat OpenShift AI (RHOAI)Not affected
redhatRed Hat OpenShift AI (RHOAI)Not affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
9 Fixed fence-agents-eaton-snmp-4.10.0-98.el9_7.5.noarch.rpm
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 0.6.1-1+deb13u1
sid Fixed 0.6.2-1
forky Fixed 0.6.2-1
bullseye Fixed 0.4.8-1+deb11u1
bookworm Fixed 0.4.8-3+deb12u1
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”
rockylinux Rocky Linux Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”

Package impact

EcosystemPackageVulnerableFixed
python PyPIpyasn1>=0.6.1,<0.6.20.6.2

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.