{
  "document": {
    "aggregate_severity": {
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "* SECURITY UPDATE: Quadratic complexity in OBJECT IDENTIFIER decoding\n     - debian/patches/CVE-2026-59885.patch: accumulate arcs in a list instead\n       of repeated tuple concatenation in the BER decoder and encoder\n     - CVE-2026-59885\n   * SECURITY UPDATE: Uncontrolled resource consumption converting univ.Real\n     - debian/patches/CVE-2026-59886.patch: use math.ldexp for base 2 and\n       reject base-10 exponents above sys.float_info.max_10_exp in\n       Real.__float__, instead of exact big-integer exponentiation\n     - CVE-2026-59886",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789671837",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789671837"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/debian11els/advisories/2026/clsa-2026_1789671837.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-17T19:04:59Z",
      "generator": {
        "date": "2026-09-17T19:04:59Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1789671837",
      "initial_release_date": "2026-09-17T19:04:59Z",
      "revision_history": [
        {
          "date": "2026-09-17T19:04:59Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "Fix CVE(s): CVE-2026-59885, CVE-2026-59886"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 11",
                "product": {
                  "name": "Debian 11",
                  "product_id": "Debian-11",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:11:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "pypy-pyasn1-0:0.4.8-1+deb11u2+tuxcare.els1.all",
                "product": {
                  "name": "pypy-pyasn1-0:0.4.8-1+deb11u2+tuxcare.els1.all",
                  "product_id": "pypy-pyasn1-0:0.4.8-1+deb11u2+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/pypy-pyasn1@0.4.8-1%2Bdeb11u2%2Btuxcare.els1?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "python3-pyasn1-0:0.4.8-1+deb11u2+tuxcare.els1.all",
                "product": {
                  "name": "python3-pyasn1-0:0.4.8-1+deb11u2+tuxcare.els1.all",
                  "product_id": "python3-pyasn1-0:0.4.8-1+deb11u2+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/python3-pyasn1@0.4.8-1%2Bdeb11u2%2Btuxcare.els1?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "python-pyasn1-doc-0:0.4.8-1+deb11u2+tuxcare.els1.all",
                "product": {
                  "name": "python-pyasn1-doc-0:0.4.8-1+deb11u2+tuxcare.els1.all",
                  "product_id": "python-pyasn1-doc-0:0.4.8-1+deb11u2+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/python-pyasn1-doc@0.4.8-1%2Bdeb11u2%2Btuxcare.els1?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "pypy-pyasn1-0:0.4.8-1+deb11u2+tuxcare.els1.all as a component of Debian 11",
          "product_id": "Debian-11:pypy-pyasn1-0:0.4.8-1+deb11u2+tuxcare.els1.all"
        },
        "product_reference": "pypy-pyasn1-0:0.4.8-1+deb11u2+tuxcare.els1.all",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-pyasn1-0:0.4.8-1+deb11u2+tuxcare.els1.all as a component of Debian 11",
          "product_id": "Debian-11:python3-pyasn1-0:0.4.8-1+deb11u2+tuxcare.els1.all"
        },
        "product_reference": "python3-pyasn1-0:0.4.8-1+deb11u2+tuxcare.els1.all",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python-pyasn1-doc-0:0.4.8-1+deb11u2+tuxcare.els1.all as a component of Debian 11",
          "product_id": "Debian-11:python-pyasn1-doc-0:0.4.8-1+deb11u2+tuxcare.els1.all"
        },
        "product_reference": "python-pyasn1-doc-0:0.4.8-1+deb11u2+tuxcare.els1.all",
        "relates_to_product_reference": "Debian-11"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-59885",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": "pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values. This issue is fixed in version 0.6.4.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-11:pypy-pyasn1-0:0.4.8-1+deb11u2+tuxcare.els1.all",
          "Debian-11:python-pyasn1-doc-0:0.4.8-1+deb11u2+tuxcare.els1.all",
          "Debian-11:python3-pyasn1-0:0.4.8-1+deb11u2+tuxcare.els1.all"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-59885"
        },
        {
          "category": "external",
          "summary": "https://github.com/pyasn1/pyasn1/commit/45bdb19eb7df4b3780fe9c912c63e99bffc39dd9",
          "url": "https://github.com/pyasn1/pyasn1/commit/45bdb19eb7df4b3780fe9c912c63e99bffc39dd9"
        },
        {
          "category": "external",
          "summary": "https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4",
          "url": "https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4"
        },
        {
          "category": "external",
          "summary": "https://github.com/pyasn1/pyasn1/security/advisories/GHSA-8ppf-4f7h-5ppj",
          "url": "https://github.com/pyasn1/pyasn1/security/advisories/GHSA-8ppf-4f7h-5ppj"
        }
      ],
      "release_date": "2026-07-14T17:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-17T19:03:59.842904Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1789671837",
          "product_ids": [
            "Debian-11:pypy-pyasn1-0:0.4.8-1+deb11u2+tuxcare.els1.all",
            "Debian-11:python-pyasn1-doc-0:0.4.8-1+deb11u2+tuxcare.els1.all",
            "Debian-11:python3-pyasn1-0:0.4.8-1+deb11u2+tuxcare.els1.all"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789671837"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-59886",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": "pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print, log, or compare decoded objects. This issue is fixed in version 0.6.4.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-11:pypy-pyasn1-0:0.4.8-1+deb11u2+tuxcare.els1.all",
          "Debian-11:python-pyasn1-doc-0:0.4.8-1+deb11u2+tuxcare.els1.all",
          "Debian-11:python3-pyasn1-0:0.4.8-1+deb11u2+tuxcare.els1.all"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-59886"
        },
        {
          "category": "external",
          "summary": "https://github.com/pyasn1/pyasn1/commit/e60c691cb91addb8fcefa2f537e85ede6fb1e886",
          "url": "https://github.com/pyasn1/pyasn1/commit/e60c691cb91addb8fcefa2f537e85ede6fb1e886"
        },
        {
          "category": "external",
          "summary": "https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4",
          "url": "https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4"
        },
        {
          "category": "external",
          "summary": "https://github.com/pyasn1/pyasn1/security/advisories/GHSA-hm4w-wwcw-mr6r",
          "url": "https://github.com/pyasn1/pyasn1/security/advisories/GHSA-hm4w-wwcw-mr6r"
        }
      ],
      "release_date": "2026-07-14T17:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-17T19:03:59.842904Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1789671837",
          "product_ids": [
            "Debian-11:pypy-pyasn1-0:0.4.8-1+deb11u2+tuxcare.els1.all",
            "Debian-11:python-pyasn1-doc-0:0.4.8-1+deb11u2+tuxcare.els1.all",
            "Debian-11:python3-pyasn1-0:0.4.8-1+deb11u2+tuxcare.els1.all"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789671837"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}