CVE-2018-6003: Debian Linux

High severity, CVSS 7.5. EPSS: 2.8% chance of exploitation in the next 30 days.

An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 before 4.13. Unlimited recursion in the BER decoder leads to stack exhaustion and DoS.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Fedoraproject Fedora: version 26 only; version 27 only
  • GNU LIBTASN1: up to and including 4.12

Published 2018-01-22. Last modified 2026-06-17.