Описание
A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).
Отчет
This vulnerability is rated Moderate for Red Hat. GnuTLS is susceptible to a denial of service attack due to excessive CPU and memory consumption. This occurs when processing specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs) during certificate verification.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | gnutls | Will not fix | ||
| Red Hat Enterprise Linux 7 | gnutls | Will not fix | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred | ||
| Red Hat Enterprise Linux 10 | gnutls | Fixed | RHSA-2026:3477 | 02.03.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | gnutls | Fixed | RHSA-2026:6618 | 06.04.2026 |
| Red Hat Enterprise Linux 8 | gnutls | Fixed | RHSA-2026:5585 | 24.03.2026 |
| Red Hat Enterprise Linux 8 | gnutls | Fixed | RHSA-2026:5585 | 24.03.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | gnutls | Fixed | RHSA-2026:33125 | 29.06.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | libtasn1 | Fixed | RHSA-2026:33125 | 29.06.2026 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | gnutls | Fixed | RHSA-2026:33125 | 29.06.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).
A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).
A flaw was found in GnuTLS. This vulnerability allows a denial of serv ...
A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).
EPSS
5.3 Medium
CVSS3