PT-2026-95378 · Unknown · Rustls-Webpki
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
rustls-webpki versions 0.103.0 through 0.103.12
rustls-webpki versions 0.104.0-alpha through 0.104.0-alpha.6
Description
A denial of service occurs due to a panic in the
bit string flags() function within src/der.rs. The issue arises when the function processes a named-bit BIT STRING with content exactly [0x00] (zero padding bits and no data bytes), causing a subtraction underflow on an empty slice and a subsequent index-out-of-bounds panic. This condition is reachable via the BorrowedCertRevocationList::from der() and OwnedCertRevocationList::from der() public APIs when a Certificate Revocation List (CRL) contains an issuingDistributionPoint extension with a specifically crafted onlySomeReasons value. This panic can occur before the CRL signature is verified. Exploitation requires an application to explicitly enable CRL revocation checking by passing RevocationOptions to the verify for usage() function and parsing CRL bytes from an attacker-controlled source. The default configuration does not use RevocationOptions and is therefore not affected.Recommendations
Update rustls-webpki versions 0.103.0 through 0.103.12 to version 0.103.13.
Update rustls-webpki versions 0.104.0-alpha through 0.104.0-alpha.6 to version 0.104.0-alpha.7.
Exploit
Fix
DoS
Out of bounds Read
Integer Underflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rustls-Webpki