yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2025-13151
Component Overview
Vulnerability Overview
Name
CVE-2025-13151
Source
NVD (
link
)
Debian (
link
)
Description
Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.
CWEs
CWE-787
Published Date
Jan 7, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://gitlab.com/gnutls/libtasn1
Product
https://gitlab.com/gnutls/libtasn1/-/merge_requests/121
Patch
http://www.openwall.com/lists/oss-security/2026/01/08/5
Mailing List
https://www.kb.cert.org/vuls/id/271649
Third Party Advisory
Analysis
#
Affected Component
Analysis
libtasn1
Patched
Vulnerability Ratings
#
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
libtasn1
buildroot
2025.02.x
4.21.0
Not Affected
libtasn1
buildroot
master
4.21.0
Not Affected
libtasn1
openwrt
master
4.19.0-r2
Not Affected
libtasn1
openwrt
openwrt-25.12
4.19.0-r2
Not Affected
libtasn1
yocto
kirkstone
4.20.0
Patched
libtasn1
yocto
master
4.21.0
Not Affected
Resolved with patches
#
libtasn1 (yocto:kirkstone)
#
Title
Author
Resolve
1
Fix for CVE-2025-13151 Buffer overflow
Vijay Sarvepalli <vssarvepalli@cert.org>
CVE-2025-13151
libtasn1 (yocto:scarthgap)
#
Title
Author
Resolve
1
Fix for CVE-2025-13151 Buffer overflow
Vijay Sarvepalli <vssarvepalli@cert.org>
CVE-2025-13151