Описание
A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).
Отчет
This vulnerability is rated Moderate for Red Hat. GnuTLS is susceptible to a denial of service attack due to excessive CPU and memory consumption. This occurs when processing specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs) during certificate verification.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | gnutls | Will not fix | ||
| Red Hat Enterprise Linux 7 | gnutls | Will not fix | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred | ||
| Red Hat Enterprise Linux 10 | gnutls | Fixed | RHSA-2026:3477 | 02.03.2026 |
| Red Hat Enterprise Linux 8 | gnutls | Fixed | RHSA-2026:5585 | 24.03.2026 |
| Red Hat Enterprise Linux 8 | gnutls | Fixed | RHSA-2026:5585 | 24.03.2026 |
| Red Hat Enterprise Linux 9 | gnutls | Fixed | RHSA-2026:4188 | 10.03.2026 |
| Red Hat Enterprise Linux 9 | gnutls | Fixed | RHSA-2026:4188 | 10.03.2026 |
| Red Hat Ceph Storage 8 | rhceph/rhceph-8-rhel9 | Fixed | RHSA-2026:5606 | 24.03.2026 |
| Red Hat Insights proxy 1.5 | insights-proxy/insights-proxy-container-rhel9 | Fixed | RHSA-2026:4655 | 16.03.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).
A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).
A flaw was found in GnuTLS. This vulnerability allows a denial of serv ...
A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).
EPSS
5.3 Medium
CVSS3