Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-09766

Опубликовано: 01 июн. 2026
Источник: fstec
CVSS3: 3.7
CVSS2: 2.6
EPSS Низкий

Описание

Уязвимость криптографической библиотеки GnuTLS связана с раскрытием информации на основании временных расхождений. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, получить несанкционированный доступ к защищаемой информации

Вендор

Red Hat Inc.
Сообщество свободного программного обеспечения
ООО «Ред Софт»
Amazon.com Inc.
Canonical Ltd.
Free Software Foundation, Inc.

Наименование ПО

Red Hat Enterprise Linux
Debian GNU/Linux
РЕД ОС
Amazon Linux
Ubuntu
Red Hat Discovery
Red Hat Update Infrastructure
Red Hat Hardened Images
GnuTLS

Версия ПО

6 (Red Hat Enterprise Linux)
7 (Red Hat Enterprise Linux)
8 (Red Hat Enterprise Linux)
12 (Debian GNU/Linux)
7.3 (РЕД ОС)
9 (Red Hat Enterprise Linux)
2023 (Amazon Linux)
24.04 LTS (Ubuntu)
10 (Red Hat Enterprise Linux)
13 (Debian GNU/Linux)
2 (Red Hat Discovery)
9.6 Extended Update Support (Red Hat Enterprise Linux)
8.0 (РЕД ОС)
10.0 Extended Update Support (Red Hat Enterprise Linux)
5 (Red Hat Update Infrastructure)
- (Red Hat Hardened Images)
26.04 LTS (Ubuntu)
до 3.8.13 (GnuTLS)
9.4 Update Services for SAP Solutions (Red Hat Enterprise Linux)

Тип ПО

Операционная система
Прикладное ПО информационных систем
Программное средство защиты

Операционные системы и аппаратные платформы

Red Hat Inc. Red Hat Enterprise Linux 6
Red Hat Inc. Red Hat Enterprise Linux 7
Red Hat Inc. Red Hat Enterprise Linux 8
Сообщество свободного программного обеспечения Debian GNU/Linux 12
ООО «Ред Софт» РЕД ОС 7.3
Red Hat Inc. Red Hat Enterprise Linux 9
Amazon.com Inc. Amazon Linux 2023
Canonical Ltd. Ubuntu 24.04 LTS
Red Hat Inc. Red Hat Enterprise Linux 10
Сообщество свободного программного обеспечения Debian GNU/Linux 13
Red Hat Inc. Red Hat Enterprise Linux 9.6 Extended Update Support
ООО «Ред Софт» РЕД ОС 8.0
Red Hat Inc. Red Hat Enterprise Linux 10.0 Extended Update Support
Canonical Ltd. Ubuntu 26.04 LTS
Red Hat Inc. Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Уровень опасности уязвимости

Низкий уровень опасности (базовая оценка CVSS 2.0 составляет 2,6)
Низкий уровень опасности (базовая оценка CVSS 3.1 составляет 3,7)

Возможные меры по устранению уязвимости

Использование рекомендаций:
Для GnuTLS:
https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-13
Для Ред ОС:
https://redos.red-soft.ru/search/?iblock_id=24&q=CVE-2026-5419
Для Debian GNU/Linux:
https://security-tracker.debian.org/tracker/CVE-2026-5419
Для Ubuntu:
https://ubuntu.com/security/CVE-2026-5419
Для Amazon Linux:
https://explore.alas.aws.amazon.com/CVE-2026-5419.html
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-5419

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 31%
0.00379
Низкий

3.7 Low

CVSS3

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 3.7
redos
около 1 месяца назад

Уязвимость gnutls

CVSS3: 3.7
ubuntu
около 2 месяцев назад

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.

CVSS3: 3.7
redhat
3 месяца назад

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.

CVSS3: 3.7
nvd
около 2 месяцев назад

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.

CVSS3: 3.7
msrc
около 2 месяцев назад

Guntls: gnutls: information disclosure via timing side-channel in pkcs#7 padding removal

EPSS

Процентиль: 31%
0.00379
Низкий

3.7 Low

CVSS3

2.6 Low

CVSS2