Bug#1144080: gnutls28: mismege of CVE-2025-13151

Bastien Roucaries <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <2465936.MzOyzyC30C@debian-ei>
Le mardi 11 août 2026, 07:57:30 heure d’été d’Europe centrale Salvatore Bonaccorso a écrit :
> HI Charles,
> 
> On Tue, Aug 11, 2026 at 01:52:05AM -0300, Carlos Henrique Lima Melara wrote:
> > Hi,
> > 
> > On Mon, Aug 10, 2026 at 09:55:46PM +0200, Bastien Roucaries wrote:
> > > 
> > > CVE-2025-13151 (libtasn1 - off-by-one in asn1_expand_octet_string, fixed in
> > > 4.20.0)
> > > 
> > >  The fix changes:
> > >    char name[2 * ASN1_MAX_NAME_SIZE + 1]
> > > 
> > >  to:
> > >    char name[2 * ASN1_MAX_NAME_SIZE + 2]
> > > 
> > >  This applies to two functions: asn1_expand_any_defined_by and
> > >  asn1_expand_octet_string.
> > > 
> > > gnutls28 vendor libtasn1 internally and show a partial fix -
> > > asn1_expand_any_defined_by has been updated (+ 2 present) but
> > > 
> > > asn1_expand_octet_string still carries the vulnerable version (+ 1):
> > >    - gnutls28 (lib/minitasn1/decoding.c)
> > > 
> > >      asn1_expand_any_defined_by: patched
> > >      asn1_expand_octet_string: VULNERABLE
> > > 
> > > Thanks Gajendra Nath Soren
> > 
> > bullseye/bookworm are also affected in asn1_expand_octet_string and
> > buster/stretch are affected in both asn1_expand_octet_string and
> > asn1_expand_any_defined_by.
> > 
> > I don't know exactly how to deal with this case of embedded code copies
> > in the security-tracker so, secteam, could you assist here? (do we just
> > mark gnutls28 as affected by CVE-2025-13151?)
> > 
> > Although it has the minitasn1 code embedded, I don't think it's being
> > used. Looking closer, the configure script is using the distro version
> > [1]:
> > 
> > checking for libtasn1 >= 4.9... yes
> > checking whether to use the included minitasn1... no
> > 
> > Same goes for sid/forky [2], trixie [3], bookworm [1], bullseye [4],
> > buster[5] and stretch [6]. So I think this is a case where the
> > vulnerability is only in the source code and not in the built binary
> > (provided libtasn1 shared library has been updated with the fix).
> 
> Generally: If the embedded source is not used at all it has no
> security impact, so our usual approach here is to not even list
> src:gnutsl28 in the respective CVE entry for the libtasn1-6 issue.  If
> an embedded source OTOH is used and has a security impact on the
> embedding source, then it can/should be listed.
> 
> So I guess #1144080 can be closed (or if Andreas wants to track the
> update to the embeded copy then RC level is defintively not warranted,
> and the bug can be downgraded to minor and then closed once the
> embedded copy is updated upstream to include the fix. But TBH I do not
> think this overhead is needed here).

Please report upstream or coordinate with upstream here, or let me report upstream.

I was also burned a long time ago by embeded code copy that is compiled due to upstream change, so for lib it is interesting sometimes to
repack in order to avoid upstream change that get vendoring compiled by accident

thanks
> 
> Regards,
> Salvatore
>
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmp62s0ACgkQADoaLapB
CF+CQBAAh43uwLtw9wxAsbLRKaITCP5qVkkVluRc8vE0WDrnwNq0eU+CpXeVes9m
fRzkEP5bFprTVraY+XIls6j7w6Kw7KV7nrxGA/O2Av/1huaV3jtZ4QgROmJAtor7
L+Me9nWZ8Uf4VjiDKoqi6uysCA0J37FvSYrpGWJccBOmEsRgYrDrhq0/7KZ8a4qC
tNBp5iOKHOqEVuNduGMERr20jx5CBJnavOP+HGVf3PpKKxXdIlSwVMRRdS5/Kvgt
KwmB5JFhCFl4qs7HXq1WL/SMSPvvNBXAQkAqrXw1XVuWsgiF9vEtSqUPgIW+qFU8
KZAriPoFMAdy/THg5gy04GNBxvL+nf+4WochANLDLg8gbXAehTpslHaqofNeBvV5
aWPy0NMahMIdJQa10gfXpl5RPRh6EbgFXG9GunOzhLvFWxvClw4Q+6z4NxDrC5lt
rjkVbaBenDd9paMNiOuog4HoxlZfGLnFr3+WCP/FdU5BAtoG0oIr07BJDHjwDXiF
eAi43OZLszGvQOz4LXVe/p9lw6mySIeo7Ft3LfsF0Rn5YYqrDy5LOncUIn87qNCg
p6Nz3EX9DGPUha9+0si7aKB9TK7/f2BnEjONvKBAudFuY5vMNSgFO3mH+48VZvNm
Gqh/gnccLsEhRmWeBWF0mWldDQ4zpg1nc8eCYXf1F9UfEgvUmIk=
=IfYJ
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.