Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5260

Опубликовано: 29 апр. 2026
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gnutlsOut of support scope
Red Hat Enterprise Linux 7gnutlsNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-hypershift-rhel9Under investigation
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat Enterprise Linux 10gnutlsFixedRHSA-2026:2061326.05.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportgnutlsFixedRHSA-2026:2640916.06.2026
Red Hat Enterprise Linux 8gnutlsFixedRHSA-2026:2061126.05.2026
Red Hat Enterprise Linux 8gnutlsFixedRHSA-2026:2061126.05.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportgnutlsFixedRHSA-2026:3312529.06.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportlibtasn1FixedRHSA-2026:3312529.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-126
https://bugzilla.redhat.com/show_bug.cgi?id=2467450gnutls: gnutls: Information disclosure via heap overread in RSA key exchange

EPSS

Процентиль: 50%
0.00727
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
ubuntu
2 месяца назад

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.

CVSS3: 8.2
nvd
2 месяца назад

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.

CVSS3: 8.2
msrc
около 2 месяцев назад

Gnutls: gnutls: information disclosure via heap overread in rsa key exchange

CVSS3: 8.2
debian
2 месяца назад

A flaw was found in libgnutls. A remote attacker, by sending an extrem ...

CVSS3: 8.2
github
2 месяца назад

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.

EPSS

Процентиль: 50%
0.00727
Низкий

8.2 High

CVSS3