Your message dated Thu, 29 Jan 2026 18:50:36 +0000
with message-id <[email protected]>
and subject line Bug#1125753: fixed in pyasn1 0.4.8-3+deb12u1
has caused the Debian Bug report #1125753,
regarding pyasn1: CVE-2026-23490
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1125753: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1125753
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: pyasn1
Version: 0.6.1-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for pyasn1.

CVE-2026-23490[0]:
| pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a
| Denial-of-Service issue has been found that leads to memory
| exhaustion from malformed RELATIVE-OID with excessive continuation
| octets. This vulnerability is fixed in 0.6.2.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-23490
    https://www.cve.org/CVERecord?id=CVE-2026-23490
[1] https://github.com/pyasn1/pyasn1/security/advisories/GHSA-63vm-454h-vhhq
[2] 
https://github.com/pyasn1/pyasn1/commit/3908f144229eed4df24bd569d16e5991ace44970

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: pyasn1
Source-Version: 0.4.8-3+deb12u1
Done: Salvatore Bonaccorso <[email protected]>

We believe that the bug you reported is fixed in the latest version of
pyasn1, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <[email protected]> (supplier of updated pyasn1 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 23 Jan 2026 23:05:30 +0100
Source: pyasn1
Architecture: source
Version: 0.4.8-3+deb12u1
Distribution: bookworm-security
Urgency: high
Maintainer: Jan Lübbe <[email protected]>
Changed-By: Salvatore Bonaccorso <[email protected]>
Closes: 1125753
Changes:
 pyasn1 (0.4.8-3+deb12u1) bookworm-security; urgency=high
 .
   * Non-maintainer upload by the Security Team.
   * Fixed continuation octet limits in OID/RELATIVE-OID decoder 
(CVE-2026-23490)
     (Closes: #1125753)
Checksums-Sha1:
 ad449774c8de4f5bb7f44dca6bbee373061aa677 2397 pyasn1_0.4.8-3+deb12u1.dsc
 e0fa19f8fda46a1fa2253477499b116b33f67175 146820 pyasn1_0.4.8.orig.tar.gz
 a673afea760678bbaa950fb5b16dde73babcb056 7212 
pyasn1_0.4.8-3+deb12u1.debian.tar.xz
 aa9a81a9465d77bb5e0c5b503e4a17d7a22a4772 6811 
pyasn1_0.4.8-3+deb12u1_source.buildinfo
Checksums-Sha256:
 3ad7e0ca222e87949a07849cb69b23ca398533463dac6accf0d18e44ce32c59e 2397 
pyasn1_0.4.8-3+deb12u1.dsc
 aef77c9fb94a3ac588e87841208bdec464471d9871bd5050a287cc9a475cd0ba 146820 
pyasn1_0.4.8.orig.tar.gz
 9fe1456fffd93a9e44f16c2298c8a742e0ed28fb11925fd45304331a7ab04ad6 7212 
pyasn1_0.4.8-3+deb12u1.debian.tar.xz
 d5d4f632e0f69e91a3eda9350c961d6584158c829119cb7d209ac390d87e980a 6811 
pyasn1_0.4.8-3+deb12u1_source.buildinfo
Files:
 700aed82bb8325efbf10d14e1192090d 2397 python optional 
pyasn1_0.4.8-3+deb12u1.dsc
 dffae4ff9f997a83324b3f33fe62be54 146820 python optional 
pyasn1_0.4.8.orig.tar.gz
 345b112c252de99c2d1644d4c2beb6d9 7212 python optional 
pyasn1_0.4.8-3+deb12u1.debian.tar.xz
 a4d6cf253c1a154b51842754b82b60c1 6811 python optional 
pyasn1_0.4.8-3+deb12u1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAml0AQJfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89EbxkP+wZ+1f10yMdoS5EMqEmWlNJ//Ll1+mBC
BlwywmyapVx6dg3KHwHbhAD9oiHk4AnNIlbAQzZ1NdGhPeWKAGRl30zcenQTVJ7m
gKS4YzB8vEibpHZLIJBAFOo3Kca6HESX7sZqUbk9BonIJse5h7FiNXmlKAFBArLo
+mPZe865GKdAv6BDSStFZTXUQ7W4kow0S9TkiZZICkXRYYUAHrij+sERzxw6DWvU
fW9unL2j91cgWsMjJBdLIr7mIJpsFNe2KyalflufHqhCs54gnzE4N6T0+pGybPbK
OkVBLz7lBHa7gKTLIAW9zYtMLauqul7xddf3Pef/fobftkkvjLKIVTyNPtn0uhxQ
Oxekr/2on+F/FGkFWnQfmuxFsNJpUawXIqkerJ/L78MAVZ1KDrRDzZfARjntGVhF
H2GJu5gBw96yopHdltxizXverw60SFOSaHWTf4fxOdmCkcqK9D7SGDxSC8Ub8bfS
KO9RhWHXoxBwAFbqncH7xDy33vIS5I1kaI2rs6LXPrgc9Gt0dRDqZ3Zk9UaSzqCS
X711rwGGg28ADzGZjN2NrwOk9SZvWyaNq62FbJDzTf8VzWH5yIr5Q+V/lewclxSU
gfhkbbJrMrJp6xzXfQ5EgcH9UUDwID+mQEQMd34IhW5OA7MbVs3j9HFURcQQLUDH
0q3MtPGEkHj+
=TbU6
-----END PGP SIGNATURE-----

Attachment: pgpZLQMbimI8i.pgp
Description: PGP signature


--- End Message ---

Reply via email to