Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-5419

Опубликовано: 01 июн. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gnutls28fixed3.8.13-1package
gnutls28not-affectedbullseyepackage

Примечания

  • https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-13

  • https://gitlab.com/gnutls/gnutls/-/issues/1815

  • Fixed by: https://gitlab.com/gnutls/gnutls/-/commit/1e627aa5ad95c6dc0518d94e9a009997b081a1ab (3.8.13)

  • Introduced with: https://gitlab.com/gnutls/gnutls/-/commit/4b45ad6923a7b1d296a111153663f23c13173b94 (3.7.7)

EPSS

Процентиль: 31%
0.00379
Низкий

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 2 месяцев назад

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.

CVSS3: 3.7
redhat
3 месяца назад

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.

CVSS3: 3.7
nvd
около 2 месяцев назад

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.

CVSS3: 3.7
msrc
около 2 месяцев назад

Guntls: gnutls: information disclosure via timing side-channel in pkcs#7 padding removal

CVSS3: 3.7
github
около 2 месяцев назад

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.

EPSS

Процентиль: 31%
0.00379
Низкий