Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-33845

Опубликовано: 30 апр. 2026
Источник: debian
EPSS Низкий

Описание

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gnutls28fixed3.8.13-1package

Примечания

  • https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-3

  • https://gitlab.com/gnutls/gnutls/-/issues/1811

  • Fixed by: https://gitlab.com/gnutls/gnutls/-/commit/e5b72c53c7d789d19d1d1cd10b275e87d0415413 (3.8.13)

EPSS

Процентиль: 53%
0.00805
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.

CVSS3: 7.5
redhat
3 месяца назад

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.

CVSS3: 7.5
nvd
3 месяца назад

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.

CVSS3: 8.2
msrc
3 месяца назад

Gnutls: gnutls: denial of service via dtls zero-length fragment

CVSS3: 7.5
github
3 месяца назад

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.

EPSS

Процентиль: 53%
0.00805
Низкий