Описание
A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | gnutls | Out of support scope | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-hypershift-rhel9 | Under investigation | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred | ||
| Red Hat Enterprise Linux 10 | gnutls | Fixed | RHSA-2026:20613 | 26.05.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | gnutls | Fixed | RHSA-2026:26409 | 16.06.2026 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | gnutls | Fixed | RHSA-2026:43575 | 22.07.2026 |
| Red Hat Enterprise Linux 8 | gnutls | Fixed | RHSA-2026:20611 | 26.05.2026 |
| Red Hat Enterprise Linux 8 | gnutls | Fixed | RHSA-2026:20611 | 26.05.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | gnutls | Fixed | RHSA-2026:33125 | 29.06.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | libtasn1 | Fixed | RHSA-2026:33125 | 29.06.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts.
A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts.
Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling
A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 ...
EPSS
5.3 Medium
CVSS3