Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-10028

Опубликовано: 28 мая 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A flaw was found in glib-networking. A remote attacker can exploit this vulnerability by presenting a specially crafted certificate chain to an application that uses glib-networking with the GnuTLS backend enabled and performs certificate verification. This crafted chain, which contains circular issuer relationships, can cause an infinite loop during certificate verification. The unbounded traversal consumes excessive CPU resources, leading to a denial of service for the affected process or worker.

Отчет

There's a vulnerability in the glib-networking package, where a server with a maliciously crafted certificate chain can lead the application using the glib-networking libraries with GnuTLS backend to an excessive CPU consumption and cause a Denial-of-Service as consequence of it. The vulnerability happens when the application is performing a certificate validation and the crafted certificate chain contains a circular issuer relationship. For latest glib-networking versions such as shipped with Red Hat Enterprise Linux 10, this can lead the client application to freeze when connecting to a malicious server holding the crafted certificate chain resulting in an availability impact to the specific execution on the process (A:L). For versions of glib-networking as shipped with Red Hat Enterprise Linux 9 and older, it's possible that an attacker may be able to cause a Denial-of-Service in a server application which does the same kind of validation depending on certain scenarios. Red Hat Product Security team has rated this vulnerability as having a Low impact since, in general, the result of a exploitation needs the user to be tricked to connect to a malicious server and would have a low availability impact as consequence.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10glib-networkingFix deferred
Red Hat Enterprise Linux 6glib-networkingFix deferred
Red Hat Enterprise Linux 7glib-networkingFix deferred
Red Hat Enterprise Linux 8glib-networkingFix deferred
Red Hat Enterprise Linux 9glib-networkingFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2465152glib-networking: Infinite loop in glib-networking GnuTLS backend allows remote denial of service via circular certificate chain

EPSS

Процентиль: 8%
0.00181
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
3 месяца назад

A flaw was found in glib-networking. A remote attacker can exploit this vulnerability by presenting a specially crafted certificate chain to an application that uses glib-networking with the GnuTLS backend enabled and performs certificate verification. This crafted chain, which contains circular issuer relationships, can cause an infinite loop during certificate verification. The unbounded traversal consumes excessive CPU resources, leading to a denial of service for the affected process or worker.

CVSS3: 4.3
nvd
3 месяца назад

A flaw was found in glib-networking. A remote attacker can exploit this vulnerability by presenting a specially crafted certificate chain to an application that uses glib-networking with the GnuTLS backend enabled and performs certificate verification. This crafted chain, which contains circular issuer relationships, can cause an infinite loop during certificate verification. The unbounded traversal consumes excessive CPU resources, leading to a denial of service for the affected process or worker.

CVSS3: 4.3
msrc
2 месяца назад

Glib-networking: infinite loop in glib-networking gnutls backend allows remote denial of service via circular certificate chain

CVSS3: 4.3
debian
3 месяца назад

A flaw was found in glib-networking. A remote attacker can exploit thi ...

suse-cvrf
около 2 месяцев назад

Security update for glib-networking

EPSS

Процентиль: 8%
0.00181
Низкий

4.3 Medium

CVSS3

Уязвимость CVE-2026-10028