CVE-2024-58261Infinite Loop in Sequoia

CWE-835Infinite Loop7 documents5 sources
Severity
7.5HIGHNVD
EPSS
0.0%
top 93.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 27

Description

The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

debiandebian/rust-sequoia-openpgp< rust-sequoia-openpgp 1.21.0-1 (forky)
NVDsequoia-pgp/sequoia-openpgp1.13.01.21.0
crates.iosequoia-pgp/sequoia-openpgp1.13.01.21.0
CVEListV5sequoia-pgp/sequoia1.13.01.21.0

🔴Vulnerability Details

4
OSV
CVE-2024-58261: The sequoia-openpgp crate 12025-07-27
OSV
Low severity (DoS) vulnerability in sequoia-openpgp2024-06-26
OSV
Low severity (DoS) vulnerability in sequoia-openpgp2024-06-26
GHSA
Low severity (DoS) vulnerability in sequoia-openpgp2024-06-26

📋Vendor Advisories

2
Red Hat
sequoia-openpgp: Sequoia OpenPGP: RawCertParser Infinite Loop Vulnerability2025-07-27
Debian
CVE-2024-58261: rust-sequoia-openpgp - The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop ...2024