Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-50346

Опубликовано: 24 июн. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-50346: gnutls security fix update (IMPORTANT)

[3.8.10-4_fips]

  • Add FIPS package change: add fips suffix to Release and set Epoch to 10 [Orabug: 35925409]
  • Update FIPS module name for Oracle Linux [Orabug: 35925409]

[3.8.10-4]

  • Fix CVE-2026-33846 (DTLS fragment reassembly, High, heap overwrite)
  • Fix CVE-2026-42009 (DTLS fragment reassembly, High, undefined behaviour)
  • Fix CVE-2026-33845 (DTLS fragment reassembly, High, heap overread)
  • Fix CVE-2026-42010 (PSK authentication, High, authentication bypass)
  • Fix CVE-2026-3833 (Name constraints, Medium, name constraint bypass)
  • Fix CVE-2026-42011 (Name constraints, Medium, name constraint bypass)
  • Fix CVE-2026-42012 (CN fallback, Medium, certificate misuse)
  • Fix CVE-2026-42013 (CN fallback, Medium, certificate misuse)
  • Fix CVE-2026-42014 (PKCS#11 PIN change, Medium, use-after-free)
  • Fix CVE-2026-5260 (PKCS#11 RSA, Medium, heap overread)
  • Fix CVE-2026-42015 (PKCS#12 appending, Low, heap overwrite)
  • Fix CVE-2026-3832 (OCSP, Low, revocation bypass)
  • Fix CVE-2026-5419 (PKCS#7, Low, timing side-channel)
  • Fix upstream security issue #1808 (PSK rehandshake)
  • Fix upstream security issue #1810 (EKU OID prefix match)
  • Fix upstream security issue #1813 (pkcs11-provider persistent keys)
  • Fix upstream security issue #1818 (RSA correctness, OpenSSL format import)
  • Fix upstream security issue #1819 (PKCS#11 trust removal error path)
  • Fix upstream security issue #1822 (SCT extension parser OOB read)
  • Fix upstream security issue #1841 (key zeroization in hybrid kex)
  • Fix upstream security issue #1823 (malformed certtool template)
  • Fix upstream security issue #1817 (session parameter loading robustness)
  • Fix upstream security issue #1820 (PKCS#11 KDF succeeding w/o deriving)
  • gnutls-3.8.10-CVE-2025-9820.patch: update Makefile.in

[3.8.10-3]

  • Fix PKCS#11 token initialization label overflow (CVE-2025-9820)
  • Fix name constraint processing performance issue (CVE-2025-14831)

[3.8.10-2]

  • Reinstate and update the prematurely dropped rekeying patch

[3.8.10-1]

  • Rebase to 3.8.10
  • Revert defaulting to PBMAC1 in FIPS mode
  • Revert unapproving 1024-, 1280-, 1536- and 1792-bit RSA verification

Связанные уязвимости

suse-cvrf
2 месяца назад

Security update for gnutls

rocky
около 2 месяцев назад

Important: gnutls security update

rocky
около 2 месяцев назад

Important: gnutls security update

oracle-oval
около 1 месяца назад

ELSA-2026-20612: gnutls security update (IMPORTANT)

suse-cvrf
2 месяца назад

Security update for gnutls