CVE-2024-27355: Debian Linux

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. When processing the ASN.1 object identifier of a certificate, a sub identifier may be provided that leads to a denial of service (CPU consumption for decodeOID).

Affected products

  • Debian Debian Linux: version 10.0 only
  • Phpseclib Phpseclib: from 1.0.0, before 1.0.23 (fixed in 1.0.23); from 2.0.0, before 2.0.47 (fixed in 2.0.47); from 3.0.0, before 3.0.36 (fixed in 3.0.36)

Published 2024-03-01. Last modified 2026-06-17.