Your message dated Tue, 21 Jul 2026 09:33:48 +0000
with message-id <[email protected]>
and subject line Bug#1142388: fixed in pyasn1 0.6.4-1
has caused the Debian Bug report #1142388,
regarding pyasn1: CVE-2026-59884 CVE-2026-59885 CVE-2026-59886
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1142388: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142388
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: pyasn1
Version: 0.6.3-1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerabilities were published for pyasn1.
CVE-2026-59884[0]:
| pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the
| BER decoder shared by the CER and DER codecs parses long-form tags
| by accumulating continuation octets without an upper bound on the
| tag ID size, allowing a crafted input to force construction of an
| arbitrarily large integer with CPU cost growing quadratically and to
| trigger unhandled ValueError exceptions in Python 3.11+ error
| formatting paths. Any application decoding untrusted BER, CER, or
| DER input is affected. This issue is fixed in version 0.6.4.
CVE-2026-59885[1]:
| pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the
| BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-
| OID values in quadratic time relative to the number of arcs, so a
| small crafted payload containing an OID with many arcs consumes
| excessive CPU per decode() call and can deny service to applications
| that decode untrusted ASN.1 data. The corresponding encoders have
| the same quadratic behavior when an application re-encodes
| previously decoded attacker-supplied values. This issue is fixed in
| version 0.6.4.
CVE-2026-59886[2]:
| pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the
| univ.Real type converted its mantissa, base, and exponent value to a
| Python float using exact big-integer exponentiation. A BER, CER, or
| DER encoded REAL value only a few bytes long can carry a very large
| exponent, causing float conversion through prettyPrint(), str(),
| comparison, arithmetic, int(), or an explicit float() call to
| consume excessive CPU and memory and hang applications that decode
| untrusted ASN.1 data and then print, log, or compare decoded
| objects. This issue is fixed in version 0.6.4.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-59884
https://www.cve.org/CVERecord?id=CVE-2026-59884
[1] https://security-tracker.debian.org/tracker/CVE-2026-59885
https://www.cve.org/CVERecord?id=CVE-2026-59885
[2] https://security-tracker.debian.org/tracker/CVE-2026-59886
https://www.cve.org/CVERecord?id=CVE-2026-59886
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: pyasn1
Source-Version: 0.6.4-1
Done: Colin Watson <[email protected]>
We believe that the bug you reported is fixed in the latest version of
pyasn1, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Colin Watson <[email protected]> (supplier of updated pyasn1 package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Tue, 21 Jul 2026 10:18:24 +0100
Source: pyasn1
Architecture: source
Version: 0.6.4-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <[email protected]>
Changed-By: Colin Watson <[email protected]>
Closes: 1142388
Changes:
pyasn1 (0.6.4-1) unstable; urgency=medium
.
* Team upload.
* New upstream release (closes: #1142388):
- CVE-2026-59885 (GHSA-8ppf-4f7h-5ppj): Fixed quadratic time complexity
in the OBJECT IDENTIFIER and RELATIVE-OID decoders.
- CVE-2026-59884 (GHSA-m4p7-r5rc-7g4j): Limited BER long-form tag IDs to
20 octets (140 bits), matching the OID arc limit introduced in 0.6.2.
- CVE-2026-59886 (GHSA-hm4w-wwcw-mr6r): Fixed excessive memory and CPU
consumption in Real.__float__() for values with large base-10
exponents.
* Standards-Version: 4.7.4.
Checksums-Sha1:
583b38bcc70e63593cf2e1301ac8a5dd4870f767 2556 pyasn1_0.6.4-1.dsc
c6081b97352187f33bbf689b5cb88a41f7c2a2ef 151262 pyasn1_0.6.4.orig.tar.gz
4bdfed7fa0482403f6621687bf78074a8de85230 6500 pyasn1_0.6.4-1.debian.tar.xz
6e6326dac1107b1ef796c491740b05ab851dd542 332212 pyasn1_0.6.4-1.git.tar.xz
c200a275b3cd67bf7a6444195c919b7a21fc9e5a 17542 pyasn1_0.6.4-1_source.buildinfo
Checksums-Sha256:
d824ea3b946214ac041cf68c0a1fd553ee39432a9bc0cc040a2d62e5e48e2626 2556
pyasn1_0.6.4-1.dsc
9c447d8431c947fe4c8febc4ed9e760bc29011a5b01e5c74b67025bd9fb8ce81 151262
pyasn1_0.6.4.orig.tar.gz
0c52dd4002a9806c099513ec39355e2934a1ce685597d1ea3752de6d066b345a 6500
pyasn1_0.6.4-1.debian.tar.xz
e52bbed02008d3b3b196f9e0a7f27801760d1db568c4e7d4a39d5885d4652e36 332212
pyasn1_0.6.4-1.git.tar.xz
861e1645cb693ab81c791db11f811aa5e2c2ba980fba7bea62343e112bf78bf6 17542
pyasn1_0.6.4-1_source.buildinfo
Files:
4be74adadcab698d0c9c65bfa830a5c2 2556 python optional pyasn1_0.6.4-1.dsc
8389c385b422c57820eca5f21bad64b1 151262 python optional
pyasn1_0.6.4.orig.tar.gz
bed52e196f129190a07a616c5c9fdfad 6500 python optional
pyasn1_0.6.4-1.debian.tar.xz
b988d9a0c7642ac3d3ee0bd5318b7fcd 332212 python None pyasn1_0.6.4-1.git.tar.xz
2470a7dc882e2ebfe3837ffa19c935a8 17542 python optional
pyasn1_0.6.4-1_source.buildinfo
Git-Tag-Info: tag=e2160eb58b4273dbe4612c06f772c6c714ae83c4
fp=ac0a4ff12611b6fccf01c111393587d97d86500b
Git-Tag-Tagger: Colin Watson <[email protected]>
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmpfOnMACgkQYG0ITkaD
wHkFYxAAi6xnKqJCKlDS+z7EEih5nrG8jMJYMdEvfbwbPVE37RldWUb6Us/yMv5v
TsSNguozPwIlBJrPy/CBP1E/D31TSGNehQzLh8aZ49kh/cBQO8ySzkhoL6OufOtU
BPSDFqKO12BTErDrqdHdPcxiPVZrBbiIPw6VHd0jBffNNxQ+Tvjib3qqLZ5QeWRw
2vWiIBFn0Ts7aC4ss59tgU/3nIbGBMYLwQCIlfvkLhQlwsutu1rgN3zoZX4Anvcj
fYFM78UOIlGRM7fas46M/8oLBvn5eOnEl4QcHYnevvCjIb6rCJqPtH/YiFZkGF8s
+6Em9FVG9TapLESdzX/b2On8f6WqvDU+pOjHGBd5ddrgN6fONMHR44ja0wVmN06Q
Ie6ps+JqxyLvV2aDcl1AJiMQYDFecAX+kropiiOaLC68BoTE0xDOWc86wTLEGyQy
z7QwPHvFVwpK6wus5Tx9WwTcmgu0X7lYyywCN0EvyopBZ+MSWzx1WTmi/YwpFiYa
gfO3IobCVtVUbahudZ+Q7tnAvu2hkAf6vNAzddCOgfSomfqxCgMtJKn5yOPPApbj
W6l6UAQKT5dENDbCGI2rewzjNBh7PWZu92GVgR+MMfP9JSOAoAaFKwG5vwtrL7Wy
qk5DZ1bEfcxfdP8kSAOZzKDnhnROPLRY94PfG2w+qeXVGZLb5Dc=
=NY+B
-----END PGP SIGNATURE-----
pgpZAt3f01Kmm.pgp
Description: PGP signature
--- End Message ---