Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-5260

Опубликовано: 26 мая 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gnutls28fixed3.8.13-1package

Примечания

  • https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-10

  • https://gitlab.com/gnutls/gnutls/-/issues/1814

  • Fixed by: https://gitlab.com/gnutls/gnutls/-/commit/77228f2d1ac207d2f894e5a168fbb47e5378e42f (3.8.13)

  • Fixed by: https://gitlab.com/gnutls/gnutls/-/commit/cf6bdc5e4df49e5583d3fb4d2296779785f10683 (3.8.13)

  • Introduced with: https://gitlab.com/gnutls/gnutls/-/commit/4804febddc2ed958e5ae774de2a8f85edeeff538 (gnutls_3_6_5)

EPSS

Процентиль: 51%
0.00727
Низкий

Связанные уязвимости

CVSS3: 8.2
ubuntu
2 месяца назад

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.

CVSS3: 8.2
redhat
3 месяца назад

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.

CVSS3: 8.2
nvd
2 месяца назад

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.

CVSS3: 8.2
msrc
около 2 месяцев назад

Gnutls: gnutls: information disclosure via heap overread in rsa key exchange

CVSS3: 8.2
github
2 месяца назад

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.

EPSS

Процентиль: 51%
0.00727
Низкий