Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-33845

Опубликовано: 30 апр. 2026
Источник: nvd
CVSS3: 7.5
CVSS3: 9.1
EPSS Низкий

Описание

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gnu:gnutls:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 54%
0.00805
Низкий

7.5 High

CVSS3

9.1 Critical

CVSS3

Дефекты

CWE-191
CWE-191

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.

CVSS3: 7.5
redhat
5 месяцев назад

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.

CVSS3: 8.2
msrc
4 месяца назад

Gnutls: gnutls: denial of service via dtls zero-length fragment

CVSS3: 7.5
debian
5 месяцев назад

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments wit ...

CVSS3: 9.1
redos
3 месяца назад

Уязвимость gnutls

EPSS

Процентиль: 54%
0.00805
Низкий

7.5 High

CVSS3

9.1 Critical

CVSS3

Дефекты

CWE-191
CWE-191