Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-3832

Опубликовано: 30 апр. 2026
Источник: redhat
CVSS3: 3.7

Описание

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.

Отчет

This issue has a LOW impact. A flaw in gnutls' OCSP stapling implementation allows a client with OCSP verification enabled to accept a revoked server certificate. This occurs when a multi-record OCSP response is stapled, and the client incorrectly reads the certificate status from an unrelated record, leading to an order-dependent acceptance of a revoked certificate.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gnutlsNot affected
Red Hat Enterprise Linux 7gnutlsNot affected
Red Hat Enterprise Linux 8gnutlsFix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-hypershift-rhel9Under investigation
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Enterprise Linux 10gnutlsFixedRHSA-2026:2061326.05.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportgnutlsFixedRHSA-2026:2640916.06.2026
Red Hat Enterprise Linux 9gnutlsFixedRHSA-2026:2061226.05.2026
Red Hat Enterprise Linux 9gnutlsFixedRHSA-2026:2061226.05.2026
Red Hat Discovery 2discovery/discovery-server-rhel9FixedRHSA-2026:2919724.06.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-179
https://bugzilla.redhat.com/show_bug.cgi?id=2445762gnutls: gnutls: Security bypass allows acceptance of revoked server certificates via crafted OCSP response

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
3 месяца назад

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.

CVSS3: 3.7
nvd
3 месяца назад

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.

CVSS3: 3.7
msrc
3 месяца назад

Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response

CVSS3: 3.7
debian
3 месяца назад

A flaw was found in gnutls. A remote attacker could exploit this vulne ...

CVSS3: 3.7
github
3 месяца назад

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.

3.7 Low

CVSS3