Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-42015

Опубликовано: 26 мая 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gnutls28fixed3.8.13-1package

Примечания

  • https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-11

  • https://gitlab.com/gnutls/gnutls/-/work_items/1840

  • Fixed by: https://gitlab.com/gnutls/gnutls/-/commit/a3e7c50d3e1761e5ef1d4b225507cab8f2b2c3ca (3.8.13)

EPSS

Процентиль: 51%
0.00727
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
2 месяца назад

A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts.

CVSS3: 5.3
redhat
3 месяца назад

A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts.

CVSS3: 5.3
nvd
2 месяца назад

A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts.

CVSS3: 5.3
msrc
2 месяца назад

Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling

CVSS3: 5.3
redos
около 1 месяца назад

Уязвимость gnutls

EPSS

Процентиль: 51%
0.00727
Низкий